CVE-2026-15037
XML injection vulnerability in QDom comment, CDATA and processing-instruction serialization
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.
| CWE | CWE-91 |
| Vendor | qt |
| Product | qt |
| Published | Jul 23, 2026 |
Stay Ahead of the Next One
Get instant alerts for qt qt
Be the first to know when new unknown vulnerabilities affecting qt qt are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Qt / Qt
4.0.0 < 6.12.0