CVE-2026-14449: u5cms

Medium severity, CVSS 6.4. EPSS: 0.4% chance of exploitation in the next 30 days.

u5CMS through v12.8.8 is vulnerable to reflected XSS via the ‘thanks’ parameter in multiple form components

Affected products

  • u5cms u5cms: up to and including 12.8.8

Published 2026-07-02. Last modified 2026-07-02.