CVE-2026-76572 PUBLISHED

pkp pkp-lib XSLTransformer.php _transformPHP xml external entity reference

Assigner: VulDB
Reserved: 19.08.2026 Published: 19.08.2026 Updated: 19.08.2026

A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is the function _transformPHP of the file classes/xslt/XSLTransformer.php. The manipulation results in xml external entity reference. The attack can be executed remotely. Upgrading to version 3.3.0-23, 3.4.0-11 and 3.5.0-5 is sufficient to fix this issue. The patch is identified as 78c699370ea43ae2784e1c4ace7c947d207f2b47. Upgrading the affected component is advised.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 5.1

Product Status

Vendor pkp
Product pkp-lib
Versions
  • Version 3.3.0-22 is affected
  • Version 3.4.0-10 is affected
  • Version 3.5.0-4 is affected
  • Version 3.3.0-23 is unaffected
  • Version 3.4.0-11 is unaffected
  • Version 3.5.0-5 is unaffected

Credits

  • Razielx64 (VulDB User) reporter

References

Problem Types

  • XML External Entity Reference CWE
  • Externally Controlled Reference CWE