Ad

CVE-2026-30919

HIGH CVSS 3.1: 7.6 EPSS 0.04%
Updated Mar 10, 2026
facileManager
Parameter Value
CVSS 7.6 (HIGH)
Fixed In 6.0.4
Type CWE-79 (Cross-Site Scripting (XSS))
Vendor facileManager
Public PoC No

facileManager is a modular suite of web apps built with the sysadmin in mind. Prior to 6.0.4 , stored XSS (also known as persistent or second-order XSS) occurs when an application receives data from an untrusted source and includes that data in its subsequent HTTP responses in an unsafe manner. This vulnerability was found in the fmDNS module.

This vulnerability is fixed in 6.0.4.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
Low
Partial disruption

CVSS Vector v3.1