Junglewise Threat Intelligence

CVE-2026-41147: NukeViet CMS Stored XSS in Request class

CVE-2026-41147 · Severity: high · CVSS 8.7 · Published 2026-05-22

Technologies: NukeViet CMS, nukeviet/nukeviet (Packagist). Vendors: NukeViet, Packagist.

Executive brief

NukeViet CMS, a popular content management system, is vulnerable to a security flaw where malicious code can be permanently stored on the website. An attacker can use this to steal administrator login sessions, redirect visitors to phishing sites, or deface the website. This occurs because the system fails to properly clean user-submitted content before saving it to the database.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in NukeViet CMS versions up to and including 4.5.08. The root cause is insufficient server-side input sanitization within the Request class, which primarily relies on bypassable client-side filtering for HTML tags and attributes. An unauthenticated or low-privileged attacker can intercept and modify HTTP requests to inject malicious payloads (e.g., using iframe srcdoc or event handlers) into modules like Contact or Comments. When an administrator or another user views this stored content, the payload executes, potentially leading to session hijacking via cookie theft or unauthorized actions. The vulnerability has been addressed in version 4.5.08.

Affected products

  • NukeViet NukeViet CMS <= 4.5.08

Timeline

  • 2026-05-15: advisory: GitHub Advisory published
  • 2026-05-15: patched: Fix released in version 4.5.08
  • 2026-05-22: other: NVD published date

References

Related threats