Description
A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/controller/content/ContentController.php of the component Template Rendering. This manipulation of the argument Title causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The reported GitHub issue was closed with the reason "completed".
Published: 2026-09-16
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the decode_string function of the ContentController.php file within PbootCMS's Template Rendering component. By manipulating the Title argument, an attacker can inject malicious scripts that are rendered in the browser, leading to cross‑site scripting. The flaw allows remote exploitation, as the attacker can supply the malicious Title via a remote request, and an exploit is publicly available.

Affected Systems

The flaw affects PbootCMS versions up to and including 3.2.22. Any installation that relies on the Template Rendering component and accepts user‑supplied Title values without proper sanitization is at risk.

Risk and Exploitability

With a CVSS score of 5.1, the vulnerability is considered medium severity. The EPSS score of less than 1% indicates a low probability of widespread exploitation at present, and the issue is not listed in the CISA KEV catalog. Nevertheless, because the flaw is remotely exploitable and an exploit is public, administrators should be aware that attackers can inject arbitrary scripting payloads when the Title field is manipulated.

Generated by OpenCVE AI on September 18, 2026 at 05:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest released version of PbootCMS, which includes a patch for the Template Rendering component.
  • Implement strict input validation or sanitization on the Title parameter to remove or encode potentially dangerous characters before processing.
  • Apply output encoding such as htmlspecialchars on rendered content to ensure any remaining payloads are treated as plain text.

Generated by OpenCVE AI on September 18, 2026 at 05:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/controller/content/ContentController.php of the component Template Rendering. This manipulation of the argument Title causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The reported GitHub issue was closed with the reason "completed".
Title PbootCMS Template Rendering ContentController.php decode_string cross site scripting
First Time appeared Pbootcms
Pbootcms pbootcms
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:pbootcms:pbootcms:*:*:*:*:*:*:*:*
Vendors & Products Pbootcms
Pbootcms pbootcms
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Pbootcms Pbootcms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-18T18:01:13.002Z

Reserved: 2026-09-16T07:57:40.404Z

Link: CVE-2026-92381

cve-icon Vulnrichment

Updated: 2026-09-18T18:01:05.854Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T15:19:01.493

Modified: 2026-09-18T18:18:07.913

Link: CVE-2026-92381

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T21:15:13Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')