CVE-2023-46505: Pwncyn Fancms

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Cross Site Scripting vulnerability in FanCMS v.1.0.0 allows an attacker to execute arbitrary code via the content1 parameter in the demo.php file.

Affected products

  • Pwncyn Fancms: version 1.0 only

Published 2023-10-27. Last modified 2026-06-17.