PT-2026-40623 · Kuicms · Kuicms Php Ee

Published

2026-05-13

·

Updated

2026-05-13

·

CVE-2020-37222

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Kuicms Php EE 2.0 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting crafted content through the bbs reply endpoint. Attackers can send POST requests to /web/?c=bbs&a=reply with HTML and JavaScript payloads in the content parameter to execute arbitrary scripts in users' browsers.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2020-37222

Affected Products

Kuicms Php Ee