CVE-2026-4845 describes a Cross-Site Scripting (XSS) vulnerability in dameng100 muucmf version 1.9.5.20260309, specifically within the /admin/Member/index.html file when processing the 'Search' argument. Rated Medium with a CVSS score of 4.3, this flaw allows for remote exploitation without authentication but requires user interaction, potentially leading to low integrity impact. Although an exploit has been published, there is no evidence of active exploitation, and it currently lacks significant community attention or readily available exploits in common frameworks.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Dameng100 | Muucmf | 1.9.5.20260309CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.