nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47931 CVE-2021-47931
MEDIUM
Exponent CMS 2.6 Multiple Vulnerabilities Stored XSS Authentication
Record summary
CVE-2021-47931 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
Exponent CMS 2.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts through the Title and Text Block parameters in the text editing endpoint. Attackers can inject iframe payloads with embedded SVG onload events to execute arbitrary JavaScript. The application also exposes database credentials in responses and lacks brute-force protection on authentication endpoints.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 11, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Exponent CMSBrowse Exponentcms / Exponent CMS | CVE List | Through 2.6 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBExponent CMS 2.6 - Multiple VulnerabilitiesExploitDB exploitby heinjameNot analyzed1 file
References
4ExploitDB-50611exploit
https://www.exploit-db.com/exploits/50611 Official Product Homepageproduct
https://www.exponentcms.org/ VulnCheck Advisory: Exponent CMS 2.6 Multiple Vulnerabilities Stored XSS AuthenticationThird-party advisory
https://www.vulncheck.com/advisories/exponent-cms-multiple-vulnerabilities-stored-xss-authentication