CVE-2026-105124
W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges.
| CWE | CWE-79 |
| Vendor | vincent-peugnet |
| Product | wcms |
| Published | Oct 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for vincent-peugnet wcms
Be the first to know when new medium vulnerabilities affecting vincent-peugnet wcms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
vincent-peugnet / wcms
0 โค 3.18.0
References
github.com: https://github.com/vincent-peugnet/wcms/issues/662 github.com: https://github.com/vincent-peugnet/wcms github.com: https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/class/Controllerconnect.php#L56 github.com: https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/view/templates/adminlog.php#L71 github.com: https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/view/templates/editrightbar.php#L110 vulncheck.com: https://www.vulncheck.com/advisories/w-wcms-through-3.18.0-unauthenticated-stored-xss-via-login-username-and-comments
Credits
ikram-4