CVE-2026-11772
Reflected XSS in DRIMO CMS
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that, when opened, results in arbitrary JavaScript execution in the victim's browser. Product is in End Of Life phase and will not receive any updates. However, deleting info.php file mitigates the vulnerability,
| CWE | CWE-79 |
| Vendor | drimo |
| Product | drimo cms |
| Published | Jun 23, 2026 |
| Last Updated | Jun 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for drimo drimo cms
Be the first to know when new unknown vulnerabilities affecting drimo drimo cms are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
DRIMO / DRIMO CMS
0 ≤ 1.0
References
Credits
Jarosław Przebinda Marcin Motwicki