🔐 CVE Alert

CVE-2026-18478

UNKNOWN 0.0

Stored XSS in Magnolia CMS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image. The issue was fixed in version 6.3.10

CWE CWE-79
Vendor magnolia dxp
Product magnolia cms
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for magnolia dxp magnolia cms

Be the first to know when new unknown vulnerabilities affecting magnolia dxp magnolia cms are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Magnolia DXP / Magnolia CMS
6.3.0 < 6.3.10

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/en/posts/2026/08/CVE-2026-18478 docs.magnolia-cms.com: https://docs.magnolia-cms.com/product-docs/6.3/releases/release-notes-for-magnolia-cms-6.3.10/ magnolia-cms.com: https://www.magnolia-cms.com/

Credits

Kacper Paluch Łukasz Sobański