CVE-2026-18478 PUBLISHED

Stored XSS in Magnolia CMS

Assigner: CERT-PL
Reserved: 31.07.2026 Published: 10.08.2026 Updated: 10.08.2026

Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image.

The issue was fixed in version 6.3.10

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor Magnolia DXP
Product Magnolia CMS
Versions Default: unaffected
  • affected from 6.3.0 to 6.3.10 (excl.)

Credits

  • Kacper Paluch finder
  • Łukasz Sobański finder

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE

Impacts

  • CAPEC-592 Stored XSS