CVE-2026-18957: Stored XSS in Menulux Software's Menulux Portal
Published Sep 4, 2026
·Updated
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS.
This issue affects Menulux Portal: before 20260903211448.
Affected Software
1 affected component
Menulux Software Inc. Menulux Portal<20260903211448
Event History
Sep 4, 2026
CVE Published
via MITRE·11:44 AM
Data Sourced
via MITRE·11:44 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access and user interaction are required for exploitation?
An attacker needs low-privileged access to the portal to submit the malicious stored content. A user must then interact with the affected page or content for the XSS payload to execute.
2
Which Menulux Portal versions are affected?
Menulux Portal versions before 20260903211448 are affected. The provided information does not identify any other affected products.