CVE-2026-25558 PUBLISHED

QloApps 1.7.0 Stored XSS via SVG File Upload in Admin File Manager

Assigner: VulnCheck
Reserved: 02.02.2026 Published: 08.06.2026 Updated: 08.06.2026

QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through the file manager to execute arbitrary scripts in the browser of any user who subsequently views the file.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 4.8

Product Status

Vendor QloApps
Product QloApps
Versions Default: affected
  • affected from 0 to 1.7.0 (incl.)

Credits

  • Chia Min Jun Lennon finder
  • VulnCheck finder

References

Problem Types

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE