Article

    Cyber News / Article / Vulnerability in Magnolia CMS software

    Vulnerability in Magnolia CMS software
    CE
    CERT Polska-2026-08-10

    Vulnerability in Magnolia CMS software

    CERT Polska has received a report about vulnerability in Magnolia CMS software and participated in coordination of its disclosure.

    The vulnerabilityCVE-2026-18478: Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image.

    The issue was fixed in version 6.3.10

    We thank Kacper Paluch and Łukasz Sobański for the responsible vulnerability report.

    Original source