Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/eddy8/LightCMS/issues/38 |
|
Fri, 03 Apr 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reflected XSS in LightCMS Admin Menus via Modified Referer |
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lightcms Project
Lightcms Project lightcms |
|
| CPEs | cpe:2.3:a:lightcms_project:lightcms:2.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Lightcms Project
Lightcms Project lightcms |
Sun, 29 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reflected XSS in LightCMS Admin Menus via Modified Referer | |
| Weaknesses | CWE-79 |
Fri, 27 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reflected XSS via Referer Header in LightCMS 2.0 Admin Menus | |
| Weaknesses | CWE-79 |
Fri, 27 Mar 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Reflected XSS via Referer Header in LightCMS 2.0 Admin Menus | |
| Weaknesses | CWE-79 |
Fri, 27 Mar 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eddy8
Eddy8 lightcms |
|
| Vendors & Products |
Eddy8
Eddy8 lightcms |
Thu, 26 Mar 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 26 Mar 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A reflected cross-site scripting (XSS) vulnerability in the /admin/menus component of Lightcms v2.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via modifying the referer value in the request header. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-10T13:53:08.108Z
Reserved: 2026-03-04T00:00:00.000Z
Link: CVE-2026-29934
Updated: 2026-03-26T18:15:17.220Z
Status : Modified
Published: 2026-03-26T15:16:36.017
Modified: 2026-05-10T14:16:49.260
Link: CVE-2026-29934
No data.
OpenCVE Enrichment
Updated: 2026-04-03T09:39:02Z