云虫漏洞库

CVE-2026-18478 - Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image. The issue was fixed in version 6.3.10 - 漏洞详情

漏洞编号:CVE-2026-18478

风险等级:未知

漏洞来源:CVE

CVE 编号:CVE-2026-18478

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-79

发布/更新时间:2026-08-10 / 2026-08-28

漏洞描述

Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image.




The issue was fixed in version 6.3.10

相关链接

相关漏洞

« 返回首页