CVE-2026-29934
EUVD-2026-1621126.03.2026, 15:16
A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referer value in the request header.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lightcms_project | lightcms | 2.0 |
𝑥
= Vulnerable software versions