Vulnerability Description
Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image. The issue was fixed in version 6.3.10
Related Weaknesses (CWE)
References
- https://cert.pl/en/posts/2026/08/CVE-2026-18478
- https://docs.magnolia-cms.com/product-docs/6.3/releases/release-notes-for-magnol
- https://www.magnolia-cms.com/
FAQ
What is CVE-2026-18478?
CVE-2026-18478 is a documented vulnerability. Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed w...
How severe is CVE-2026-18478?
CVSS scoring is not yet available for CVE-2026-18478. Check NVD for updates.
Is there a patch for CVE-2026-18478?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.