CVE-2026-5249General

LOWCVSS 2.0 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record Endpoint. Performing a manipulation of the argument value.content results in cross site scripting. It is possible to initiate the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-01: 3Technical Details · 2026-04-01: 104-01
Signal classification1 categories
General
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-5249 📊 Severity: 3.5 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-5249 #CVE-2026-5249 #CVE #Low #CyberSecurity #InfoSec https://t.co/spxql3BQUW

    Post summary

    The tweet is a basic CVE alert noting a low‑severity vulnerability, with no additional technical details, exploit code, or patch information.

    0000027
    123 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-5249 A vulnerability was found in gougucms 4.08.18. This impacts an unknown function of the file \gougucms-master\app\admin\view\user\record.html of the component Record End… https://www.cve.org/CVERecord?id=CVE-2026-5249

    Post summary

    The text briefly notes a CVE in gougucms but provides no technical details, PoC, patch, or exploitation evidence.

    00000100
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-5249 - gougucms Record Endpoint record.html cross site scripting Intel Report: https://ift.tt/dy8IUQh

    Post summary

    An alert references CVE‑2026‑5249, a XSS flaw in gougucms Record Endpoint record.html, with a link to further intel, but no details on exploitation or remediation are given.

    0000030
    281 followersView on X

Explore more