Junglewise Threat Intelligence

CVE-2026-85382: light0011 CMS stored cross-site scripting in article content

CVE-2026-85382 · Severity: medium · CVSS 4.3 · Published 2026-09-04

Technologies: Light0011 CMS.

Executive brief

light0011 CMS is a news and content management system with article publishing and commenting features. The system fails to properly encode article content before displaying it to readers, allowing attackers to inject malicious JavaScript code that executes in the browsers of anyone viewing the article. This enables theft of user sessions, website defacement, credential harvesting, and unauthorized actions on behalf of affected users.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in the Chapter content output component. The vulnerable code path retrieves article content from the database in App/Home/Model/ChapterModel.class.php (line 60-76) and calls htmlspecialchars_decode() on it, then outputs the result directly in the template (App/Home/View/Default/Chapter/oneChapter.tpl line 30) without HTML sanitization or encoding. An unauthenticated attacker can inject malicious markup (e.g., <svg/onload=alert()>) via the exposed chapter creation endpoint, which is stored in the database and executed in every reader's browser. The exploit is public and reproducible; remediation requires treating article content as untrusted data and applying strict server-side HTML allowlisting.

Affected products

  • light0011 CMS commit f72cf46f601efb2a0618c3814cc2f61380b38930 and likely others in rolling release

Timeline

  • 2026-07-18: disclosed: Issue #8 reported on GitHub
  • 2026-09-04: advisory: CVE-2026-85382 published
  • 2026-09-04: other: Exploit confirmed public; project has not responded to early notification

References