Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2480 articles · 104545 vulns · 38/41 feeds (7d)
← Back to list
—
CVE-2026-31354EXPLOITED
n/a · n/a

CVE-2026-31354: Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 a

Description

Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Group, Category or Description parameters.

Affected Products

VendorProductVersions
n/an/an/a, 2.1.1

References

  • https://github.com/liufee/cms
  • https://github.com/liufee/cms/issues/85

Related News (1 articles)

Tier C
VulDB4h ago
CVE-2026-31354 | Feehi CMS 2.1.1 Permissions Group/Category/Description cross site scripting (ID 85)
→ No new info (linked only)
CISA KEV❌ No
Actively exploited✅ Yes
PublishedApr 6, 2026
Last enriched4h agov2
Tags
XSSPermissions Module
Trending Score46
Source articles1
Independent1
Info Completeness6/14
Missing: cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-31150EXP
CVE-2026-31150: Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to
Trending: 57
CRITICALCVE-2025-57835EXP
CVE-2025-57835: An issue was discovered in RRC in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21
Trending: 50
CRITICALCVE-2026-31151EXP
CVE-2026-31151: An issue in the login mechanism of Kaleris YMS v7.2.2.1 allows attackers to bypass login verification to access the appl
Trending: 49
HIGHCVE-2026-30613EXP
CVE-2026-30613: An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Ver
Trending: 47
MEDIUMCVE-2026-31067EXP
CVE-2026-31067: A remote command execution (RCE) vulnerability in the /goform/formReleaseConnect component of UTT Aggressive 520W v3v1.7
Trending: 47

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 6, 2026
Actively Exploited
Apr 6, 2026
Discovered by ZDM
Apr 6, 2026
Updated: affectedVersions, severity, activelyExploited, tags
Apr 6, 2026

Version History

v2
Last enriched 4h ago
v2Tier C4h ago

Updated vendor and product information, set severity to HIGH, and marked the vulnerability as actively exploited.

affectedVersionsseverityactivelyExploitedtags
via VulDB
v14h ago

Initial creation