Junglewise Threat Intelligence

CVE-2026-6184: code-projects Simple Content Management System stored XSS in News Title

CVE-2026-6184 · Severity: low · CVSS 2.4 · Published 2026-04-13

Vendors: Code-Projects.

Executive brief

A vulnerability in the Simple Content Management System allows an attacker with administrative access to inject malicious scripts into news titles. When other users or visitors view the website's main page, these scripts execute in their browsers, potentially leading to the theft of login cookies or unauthorized account access. This affects the integrity of the website and the security of its visitors' sessions.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in code-projects Simple Content Management System 1.0 within the /web/admin/welcome.php component. The application fails to properly sanitize the 'News Title' argument before storing it in the database. A remote attacker with administrative privileges can submit a malicious payload that is subsequently rendered without escaping on the public-facing /web/index.php page. This can be leveraged to execute arbitrary JavaScript in the context of any user's browser session, facilitating session hijacking or cookie theft. A public exploit (PoC) is available.

Affected products

  • code-projects Simple Content Management System 1.0

Timeline

  • 2026-04-13: advisory: Initial disclosure and CVE assignment
  • 2026-04-13: disclosed: Public exploit code released on GitHub

References