CVE-2026-18478
Received Received - Intake

Stored XSS in Magnolia CMS Import Functionality

Vulnerability report for CVE-2026-18478, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-10

Last updated on: 2026-08-10

Assigner: CERT.PL

Description

Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image. The issue was fixed in version 6.3.10

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-10
Last Modified
2026-08-10
Generated
2026-08-10
AI Q&A
2026-08-10
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
magnolia cms 6.3.10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Magnolia CMS has a stored cross-site scripting (XSS) vulnerability in its import functionality. An attacker with editor-level access can inject malicious HTML or JavaScript code into the name of an uploaded image. When this image is viewed, the injected code executes in the context of the user's browser.

Impact Analysis

If exploited, this vulnerability allows an attacker to execute arbitrary scripts in the victim's browser session. This could lead to session hijacking, theft of sensitive data, or unauthorized actions performed on behalf of the user. Users with editor privileges are the primary risk group.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's integrity and confidentiality principles or HIPAA's safeguards for protected health information. Organizations using vulnerable versions may face compliance violations and potential penalties.

Mitigation Strategies

Upgrade Magnolia CMS to version 6.3.10 or later to address the Stored XSS vulnerability in import functionality.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-18478. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart