CVE-2025-50270

Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A stored Cross Site Scripting (xss) vulnerability in the "content management" feature in AnQiCMS v.3.4.11 allows a remote attacker to execute arbitrary code via a crafted script to the title, categoryTitle, and tmpTag parameters.

Published 2025-07-31. Last modified 2026-06-17.