CVE-2026-105124: W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments

Published Oct 3, 2026
·
Updated

W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges.

Affected Software

1 affected component
Vincent Peugnet Wcms<=3.18.0

Event History

Oct 3, 2026
CVE Published
via MITRE·10:30 PM
Data Sourced
via MITRE·10:30 PM
DescriptionSeverityWeakness
Oct 4, 2026
Data Sourced
via NVD·12:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Wcms installations through 3.18.0 are exposed when an administrator or editor views attacker-controlled content in either the admin log viewer or the comment editing interface. The attacker does not need an account to submit the malicious login username or comment website value.

2

What user interaction is required for exploitation?

An administrator or editor must view the affected page containing the stored payload. Failed-login payloads execute when rendered in adminlog.php, while comment website payloads execute when echoed into href attributes in editrightbar.php.

3

Are default deployments affected?

The provided information identifies the vulnerable login username and visitor comment website fields, but does not state whether those features are enabled or exposed in a default Wcms deployment.

4

How can I check whether an installation has been targeted?

Review failed-login entries shown in the admin log and visitor comment website values for unexpected markup or script-like content. The relevant stored values are those later displayed by adminlog.php or editrightbar.php.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203