Executive brief
Navigate CMS, an open-source platform used for managing website content, contains a security flaw in its blog component. An attacker could use this flaw to run malicious scripts in the web browsers of people visiting the site. This could lead to unauthorized actions being performed on behalf of users or the theft of sensitive session information.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in Navigate CMS versions prior to 2.9.5. The flaw is located in the '/blog' endpoint, where the application fails to properly sanitize user-supplied input provided via query parameters before rendering it in the HTML response. A remote, unauthenticated attacker can exploit this by tricking a user into clicking a specially crafted link, resulting in the execution of arbitrary JavaScript in the context of the victim's browser session. This issue has been addressed in version 2.9.6.
Affected products
- Navigate CMS Navigate CMS prior to 2.9.5
Timeline
- 2026-04-21: disclosed
- 2026-04-21: advisory
- 2026-04-21: patched: Fixed in version 2.9.6