AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-18478

MEDIUM · CVSS 5.1 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Magnolia CMS is susceptible to a Stored XSS vulnerability in its image import functionality, allowing attackers with editor privileges to inject malicious HTML and JavaScript into the names of uploaded images. This could lead to the execution of arbitrary scripts when the images are accessed, potentially compromising user sessions or exposing sensitive information. Organizations using affected versions of Magnolia CMS should prioritize upgrading to version 6.3.10 to mitigate this risk.

CVE
CVE-2026-18478
Severity
MEDIUM
CVSS
5.1
EPSS
0.28%

Original NVD Description

Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image. The issue was fixed in version 6.3.10