PT-2026-6078 · Unknown · Nukegraphic Cms

Carlos Budiman

+2

·

Published

2026-02-05

·

Updated

2026-02-05

·

CVE-2026-1953

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Nukegraphic CMS version 3.1.2
Description Nukegraphic CMS version 3.1.2 has a stored cross-site scripting (XSS) issue in the user profile edit functionality located at the /ngc-cms/user-edit-profile.php API endpoint. The application does not properly sanitize user input in the name field before storing it in the database and displaying it on various CMS pages. An authenticated attacker with low privileges can inject malicious JavaScript payloads through a profile edit request. These payloads are then executed site-wide whenever the affected user's name is displayed, allowing the attacker to execute arbitrary JavaScript in the context of other users' sessions, potentially leading to session hijacking or credential theft.
Recommendations Nukegraphic CMS version 3.1.2: Update to a newer, fixed version of the software.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-1953

Affected Products

Nukegraphic Cms