Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-31353

20
FAUCET Score

BRIEFING NOTE: CVE-2026-31353 Feehi CMS v2.1.1 contains an authenticated stored cross-site scripting vulnerability in its Category module that permits attackers to inject malicious scripts through the Name parameter, enabling execution of arbitrary HTML or JavaScript code. This vulnerability requires an authenticated user account to exploit, meaning access credentials are prerequisite to launching an attack. The vulnerability carries a CVSS v3.1 score of 5.4 (Medium severity) with a network-based attack vector and low complexity. Exploitation requires low privileges and user interaction, with potential impacts limited to low confidentiality and integrity compromise with no availability impact. The attack can affect multiple security domains as indicated by the CVSS scope change parameter. Current exploitation indicators remain minimal. The vulnerability is not listed on the Known Exploited Vulnerabilities (KEV) catalog, suggesting no confirmed active exploitation in the wild. The EPSS score of 0.00027 indicates this vulnerability ranks lower than 99.92 percent of all CVEs regarding empirical likelihood of exploitation. Community attention appears limited, with the vulnerability remaining inactive on threat monitoring lists.

Impacted Technologies

VendorProductVersion(s)CPE
2.1.1CPE matchmatch criteria
cpe:2.3:a:feehi:feehi_cms:2.1.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.4MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.3
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.17%
Probability of exploitation in next 30 days
EPSS Percentile
6.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0017 is in the 5th percentile among its peer group of 15,239 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

composerGHSA-664p-j3q6-p843medium

Feehi CMS has an authenticated stored cross-site scripting (XSS) vulnerability via the Category module

Apr 6, 2026

References

github.com / liufee/cms
Product
github.com / liufee/cms/issues/84
ExploitIssue Tracking