๐Ÿ” CVE Alert

CVE-2026-105124

MEDIUM 6.1

W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges.

CWE CWE-79
Vendor vincent-peugnet
Product wcms
Published Oct 3, 2026
Stay Ahead of the Next One

Get instant alerts for vincent-peugnet wcms

Be the first to know when new medium vulnerabilities affecting vincent-peugnet wcms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

vincent-peugnet / wcms
0 โ‰ค 3.18.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/vincent-peugnet/wcms/issues/662 github.com: https://github.com/vincent-peugnet/wcms github.com: https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/class/Controllerconnect.php#L56 github.com: https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/view/templates/adminlog.php#L71 github.com: https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/view/templates/editrightbar.php#L110 vulncheck.com: https://www.vulncheck.com/advisories/w-wcms-through-3.18.0-unauthenticated-stored-xss-via-login-username-and-comments

Credits

ikram-4