DRIMO CMS Reflected XSS Disclosed, No Patch
A reflected XSS vulnerability in end-of-life DRIMO CMS lets attackers execute JavaScript via a crafted search URL, with no patch coming.
CERT Polska coordinated disclosure of CVE-2026-11772, a reflected cross-site scripting vulnerability in DRIMO CMS affecting the 'q' parameter used in the search functionality. An attacker can craft a malicious URL that, when clicked by a victim, executes arbitrary JavaScript in the victim's browser context, potentially enabling session hijacking, credential theft, or further client-side attacks.
DRIMO CMS is in its End-of-Life phase and will not receive an official patch. As a workaround, CERT Polska recommends deleting the info.php file, which mitigates the vulnerability. This is a standard coordinated vulnerability disclosure with no evidence of active exploitation reported.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/06/CVE-2026-11772
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free