cvedb.io
CVE-2026-30661
MEDIUM · CVSS 6.1
EPSS exploitation probability: 0%
Published 2026-03-24T15:16:34.350 · Last modified 2026-06-17T10:32:52.107

Summary

iCMS v8.0.0 contains a Cross-Site Scripting (XSS) vulnerability in the User Management component, specifically within the index.html file. This allows remote attackers to execute arbitrary web script or HTML via the regip or loginip parameters.

Affected products

idreamsoft — icms

Does this affect you?

Add your gear to cvedb and we'll alert you only when idreamsoft ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.