CVE-2026-88415
High severity, CVSS 8.7. EPSS: 0.3% chance of exploitation in the next 30 days.
MCMS 6.1.1 through 6.2.1 is vulnerable to stored Cross-Site Scripting (XSS). The article content field `contentDetails` is excluded from the global XSS filter.
Published 2026-09-22. Last modified 2026-09-23.