CVE-2026-29840

Publication date

2026-03-24 00:00:00

Family

mitre

State

PUBLISHED

Description

JiZhiCMS v2.5.6 and before contains a Stored Cross-Site Scripting (XSS) vulnerability in the release function within app/home/c/UserController.php. The application attempts to sanitize input by filtering