Junglewise Threat Intelligence

CVE-2026-10529: westboy CicadasCMS cross site scripting in ScheduleJobController

CVE-2026-10529 · Severity: low · CVSS 2.4 · Published 2026-06-02

Executive brief

CicadasCMS, a content management system used for building and managing websites, contains a security vulnerability in its task scheduling module. An attacker with administrative privileges can inject malicious scripts that execute in the browsers of other users. This could lead to unauthorized actions being performed on behalf of other administrators or the theft of session information.

Technical details

A cross-site scripting (XSS) vulnerability exists in the Task Scheduling Management Module of CicadasCMS. The flaw is located in the ScheduleJobController.java file within the src/main/java/com/zhiliao/module/web/system/ directory. The vulnerability is caused by improper neutralization of user-supplied input during web page generation (CWE-79). A remote attacker with high privileges (PR:H) can exploit this by submitting malicious payloads that are subsequently executed in the context of a victim's browser session (UI:R). While the vendor was notified, no official patch has been released as of the advisory date.

Affected products

  • westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab

Timeline

  • 2026-06-02: advisory: NVD publication date
  • 2026-06-02: disclosed: Public exploit made available

References

Related threats