Official Product Homepageproduct
https://compo.sr/ CVE-2020-37237
MEDIUM
Composr CMS 10.0.34 Persistent Cross-Site Scripting via banners
Record summary
CVE-2020-37237 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
Composr CMS 10.0.34 contains a persistent cross-site scripting vulnerability that allows authenticated administrators to inject malicious scripts through the banner management interface. Attackers with admin credentials can inject XSS payloads in the Description field of the Add banner functionality, which execute for all website visitors when they access the home page.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 18, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Composr CMSBrowse Compo / Composr CMS | CVE List | 10.0.34 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBComposr CMS 10.0.34 - 'banners' Persistent Cross Site ScriptingExploitDB exploitby Parshwa BhavsarNot analyzed1 file
References
5Product Referenceproduct
https://compo.sr/download.htm nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37237 ExploitDB-49190exploit
https://www.exploit-db.com/exploits/49190 VulnCheck Advisory: Composr CMS 10.0.34 Persistent Cross-Site Scripting via bannersThird-party advisory
https://www.vulncheck.com/advisories/composr-cms-persistent-cross-site-scripting-via-banners