CVE-2026-36358 Details
Description
Cross Site Scripting vulnerability in Juzaweb CMS v.5.0.0 allows a remote attacker via execute arbitrary code via a crafted script to the Add Banner Ads function
A stored cross-site scripting vulnerability has been identified in Juzaweb CMS version 5.0.0. This issue allows an authenticated administrator to inject arbitrary JavaScript into the 'Add Banner Ads' function. The injected script is executed in the browser of any user who visits the homepage, including those who are not logged in.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 6, 2026CISA-ADP
Assessed May 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gist.github.com/yuhuamiao/2c984b2d7f2adb90020818f9308b5862 | CISA-ADP | ExploitTechnical Description |
| https://gist.github.com/yuhuamiao/2c984b2d7f2adb90020818f9308b5862 | [email protected] | ExploitTechnical Description |
| https://juzaweb.com/ | [email protected] | Not ApplicableVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Juzaweb CMS | 5.0.0 (semver) |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 6, 2026 | CVE Modified | CISA-ADP |
| May 6, 2026 | New CVE Received | [email protected] |
Volerion