Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.1

Cross-Site Scripting in Gougucms 4.08.18 Can Steal User Data

CVE-2026-5249
Summary

A security weakness in the Gougucms 4.08.18 system makes it possible for hackers to inject malicious code into the site, potentially allowing them to steal user data or take control of the site. This vulnerability was made public, so it's essential to update the software as soon as possible to prevent unauthorized access. Users should contact the vendor to ensure they are aware of the issue and take necessary steps to address it.

Original title
A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoint. Performing a manipulat...
Original description
A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoint. Performing a manipulation of the argument value.content results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
nvd CVSS2.0 4.0
nvd CVSS3.1 3.5
nvd CVSS4.0 5.1
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
CWE-94 Code Injection
Published: 1 Apr 2026 · Updated: 1 Apr 2026 · First seen: 1 Apr 2026