BRIEFING NOTE: CVE-2026-31353 Feehi CMS v2.1.1 contains an authenticated stored cross-site scripting vulnerability in its Category module that permits attackers to inject malicious scripts through the Name parameter, enabling execution of arbitrary HTML or JavaScript code. This vulnerability requires an authenticated user account to exploit, meaning access credentials are prerequisite to launching an attack. The vulnerability carries a CVSS v3.1 score of 5.4 (Medium severity) with a network-based attack vector and low complexity. Exploitation requires low privileges and user interaction, with potential impacts limited to low confidentiality and integrity compromise with no availability impact. The attack can affect multiple security domains as indicated by the CVSS scope change parameter. Current exploitation indicators remain minimal. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog, suggesting no confirmed active exploitation in the wild. The EPSS score of 0.00027 indicates this vulnerability ranks lower than 99.92 percent of all CVEs regarding empirical likelihood of exploitation. Community attention appears limited, with the vulnerability remaining inactive on threat monitoring lists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1.1CPE matchmatch criteria | cpe:2.3:a:feehi:feehi_cms:2.1.1:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.