Composr CMS 10.0.34 Persistent Cross-Site Scripting via banners
Published May 16, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.24%
Description
Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers with admin credentials can inject XSS payloads in the Description field of the Add banner functionality, which execute for all website visitors when they access the home page.
Affected products
-
Affected
- 10.0.34
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Compo | Composr CMS | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://compo.sr/ product
- https://compo.sr/download.htm product
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-31241 Advisory
- https://www.exploit-db.com/exploits/49190 exploit
- https://www.vulncheck.com/advisories/composr-cms-persistent-cross-site-scripting-via-banners third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://compo.sr/ | product | |
| https://compo.sr/download.htm | product | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-31241 | Advisory | |
| https://www.exploit-db.com/exploits/49190 | exploit | |
| https://www.vulncheck.com/advisories/composr-cms-persistent-cross-site-scripting-via-banners | third-party-advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data