CVE-2026-18478: Stored XSS in Magnolia CMS
Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image.
The issue was fixed in version 6.3.10
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Magnolia CMSto a version that resolves this vulnerability.Fixed in 6.3.10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18478?
CVE-2026-18478 has a risk score of 40.
How do I fix CVE-2026-18478?
To fix CVE-2026-18478, upgrade Magnolia CMS to version 6.3.10 or later.
What is CVE-2026-18478?
CVE-2026-18478 is a Stored XSS vulnerability in Magnolia CMS's import functionality.
Who is affected by CVE-2026-18478?
CVE-2026-18478 affects users of Magnolia CMS who have editor privileges.
What can an attacker do with CVE-2026-18478?
An attacker can inject arbitrary HTML and JavaScript into image names that can be executed when opening those images.