Junglewise Threat Intelligence

CVE-2026-11434: FluentCMS stored XSS in Blocks Plugin

CVE-2026-11434 · Severity: low · CVSS 2.4 · Published 2026-06-06

Technologies: Fluentcms. Vendors: Fluentcms.

Executive brief

FluentCMS, a content management system, contains a security flaw in its Blocks Plugin component. An attacker with administrative access can inject malicious scripts into website blocks, which then execute in the browsers of other users who visit the site. This could lead to unauthorized actions being performed on behalf of users, session hijacking, or the theft of sensitive information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in FluentCMS 0.0.5 within the Blocks Plugin. The application fails to properly sanitize user-supplied input in the 'Content' field when creating or editing blocks via the /admin/blocks interface. An attacker with high privileges (admin) can inject a malicious JavaScript payload that is stored on the server. When a victim views a page containing the compromised block, the script executes in their browser context. This can be used to steal session cookies or perform unauthorized actions. The vendor was notified but did not respond; a public exploit is available.

Affected products

  • FluentCMS FluentCMS 0.0.5

Timeline

  • 2026-06-06: disclosed: Public disclosure and exploit release
  • 2026-06-06: advisory: NVD publication date

References

Related threats