CVE-2026-105124: W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments
W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Wcms installations through 3.18.0 are exposed when an administrator or editor views attacker-controlled content in either the admin log viewer or the comment editing interface. The attacker does not need an account to submit the malicious login username or comment website value.
What user interaction is required for exploitation?
An administrator or editor must view the affected page containing the stored payload. Failed-login payloads execute when rendered in adminlog.php, while comment website payloads execute when echoed into href attributes in editrightbar.php.
Are default deployments affected?
The provided information identifies the vulnerable login username and visitor comment website fields, but does not state whether those features are enabled or exposed in a default Wcms deployment.
How can I check whether an installation has been targeted?
Review failed-login entries shown in the admin log and visitor comment website values for unexpected markup or script-like content. The relevant stored values are those later displayed by adminlog.php or editrightbar.php.