Magnolia-cms

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 11
    Known Exploited: 0
    2
    Critical Level Threats
    4
    High Level Threats
    4
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-18478

    Stored XSS in Magnolia CMS

    Last Modified: Aug 11, 2026
    Published: Aug 10, 2026

    CVE-2022-33098

    Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted SVG document, with JavaScript, for a profile picture.

    Last Modified: Jul 05, 2026
    Published: Jul 07, 2022

    CVE-2021-46366

    An issue in the Login page of Magnolia CMS v6.2.3 and below allows attackers to exploit both an Open Redirect vulnerability and Cross-Site Request Forgery (CSRF) in order to brute force and exfiltrate users' credentials.

    Last Modified: Nov 21, 2024
    Published: Feb 11, 2022

    CVE-2021-46365

    An issue in the Export function of Magnolia v6.2.3 and below allows attackers to execute XML External Entity attacks via a crafted XLF file.

    Last Modified: Nov 21, 2024
    Published: Feb 11, 2022

    CVE-2021-46364

    A vulnerability in the Snake YAML parser of Magnolia CMS v6.2.3 and below allows attackers to execute arbitrary code via a crafted YAML file.

    Last Modified: Nov 21, 2024
    Published: Feb 11, 2022
    Items Per Page