Record summary

CVE-2021-47931 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.

Description

Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Title and Text Block parameters in the text editing endpoint. Attackers can inject iframe payloads with embedded SVG onload events to execute arbitrary JavaScript. The application also exposes database credentials in responses and lacks brute-force protection on authentication endpoints.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 11, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListThrough 2.6affected

Proofs of concept

1

Catalogued exploits

ExploitDBExponent CMS 2.6 - Multiple VulnerabilitiesExploitDB exploitby heinjameNot analyzed1 file
ExploitDB

PoC details

References

4