CVE-2026-19447: Stored XSS in Fileorbis Informatics's FileOrbis
Published Aug 18, 2026
·Updated
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade Inc. FileOrbis allows Stored XSS.
This issue affects FileOrbis: before 16.5.
Affected Software
1 affected component
Fileorbis Informatics Services Trade Inc. FileOrbis<16.5
Event History
Aug 18, 2026
CVE Published
via MITRE·10:53 AM
Data Sourced
via MITRE·10:53 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments should be considered affected?
FileOrbis versions before 16.5 are affected. The provided data does not state whether any particular deployment or feature configuration is unaffected.
2
What does an attacker need to exploit this issue?
The vector is network-accessible, but exploitation requires low privileges and user interaction. The vulnerability is stored XSS, meaning attacker-supplied content is retained and later rendered in a web page.