Article
Cyber News / Article / Vulnerability in Magnolia CMS software

CE
CERT Polska-2026-08-10
Vulnerability in Magnolia CMS software
CERT Polska has received a report about vulnerability in Magnolia CMS software and participated in coordination of its disclosure.
The vulnerabilityCVE-2026-18478: Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image.
The issue was fixed in version 6.3.10
We thank Kacper Paluch and Åukasz SobaÅski for the responsible vulnerability report.
Related articles
in
[email protected] (The Hacker News)Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
8 days ago
in
[email protected] (The Hacker News)Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
9 days ago
Io
Ionut ArghireSAP Patches Critical Extended Passport Processing Vulnerability
3 days ago
