CVE-2020-37072: Victor CMS Project Victor CMS
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Victor CMS 1.0 contains a stored cross-site scripting vulnerability in the 'comment_author' POST parameter that allows attackers to inject malicious scripts. Attackers can submit crafted JavaScript payloads through the comment submission form to execute arbitrary code in victim browsers.
Affected products
- Victor CMS Project Victor CMS: version 1.0 only
Published 2026-02-03. Last modified 2026-06-17.