CVE-2017-9252: Finecms Project Finecms

Medium severity, CVSS 6.1. EPSS: 0.6% chance of exploitation in the next 30 days.

andrzuk/FineCMS through 2017-05-28 is vulnerable to a reflected XSS in the search page via the text-search parameter to index.php in a route=search action.

Affected products

Published 2017-05-28. Last modified 2026-06-17.