๐Ÿ” CVE Alert

CVE-2026-25558

MEDIUM 4.8

QloApps 1.7.0 Stored XSS via SVG File Upload in Admin File Manager

CVSS Score
4.8
EPSS Score
0.0%
EPSS Percentile
10th

QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through the file manager to execute arbitrary scripts in the browser of any user who subsequently views the file.

CWE CWE-79
Vendor qloapps
Product qloapps
Published Jun 8, 2026
Last Updated Jun 9, 2026
Stay Ahead of the Next One

Get instant alerts for qloapps qloapps

Be the first to know when new medium vulnerabilities affecting qloapps qloapps are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

QloApps / QloApps
0 โ‰ค 1.7.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Qloapps/QloApps/issues/1728 vulncheck.com: https://www.vulncheck.com/advisories/qloapps-stored-xss-via-svg-file-upload-in-admin-file-manager

Credits

Chia Min Jun Lennon VulnCheck