CVE-2026-25558
QloApps 1.7.0 Stored XSS via SVG File Upload in Admin File Manager
CVSS Score
4.8
EPSS Score
0.0%
EPSS Percentile
10th
QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through the file manager to execute arbitrary scripts in the browser of any user who subsequently views the file.
| CWE | CWE-79 |
| Vendor | qloapps |
| Product | qloapps |
| Published | Jun 8, 2026 |
| Last Updated | Jun 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for qloapps qloapps
Be the first to know when new medium vulnerabilities affecting qloapps qloapps are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
QloApps / QloApps
0 โค 1.7.0
References
Credits
Chia Min Jun Lennon VulnCheck