Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.1

facileManager Web Apps Allow Malicious Code Injection via URLs

CVE-2026-30918
Summary

FacileManager's web apps, prior to version 6.0.4, can inject malicious code into user's browsers when they visit a specially crafted URL. This can allow an attacker to take control of a user's session or steal sensitive information. Update to version 6.0.4 or later to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
facilemanager facilemanager <= 6.0.4 –
Original title
facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives data from an untrusted source and uses it in its H...
Original description
facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , a reflected XSS occurs when an application receives data from an untrusted source and uses it in its HTTP responses in a way that could lead to vulnerabilities. It is possible to inject malicious JavaScript code into a URL by adding a script in a parameter. This vulnerability was found in the fmDNS module. The parameter that is vulnerable to an XSS attack is log_search_query. This vulnerability is fixed in 6.0.4.
nvd CVSS3.1 7.6
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
Published: 10 Mar 2026 · Updated: 13 Mar 2026 · First seen: 11 Mar 2026