| CVE ID | CVE-2026-11772 |
| Publication date | 23 June 2026 |
| Vendor | DRIMO |
| Product | DRIMO CMS |
| Vulnerable versions | All through 1.0 |
| Vulnerability type (CWE) | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') (CWE-79) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in DRIMO CMS software and participated in coordination of its disclosure.
The vulnerability CVE-2026-11772: DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can crafted an URL that, when opened, results in arbitrary JavaScript execution in the victim's browser.
Product is in End Of Life phase and will not receive any updates. However, deleting info.php file mitigates the vulnerability,
Credits
We thank Jarosław Przebinda and Marcin Motwicki for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.