CVE-2026-37710: Omeka S vulnerability
Published Aug 28, 2026
·Updated
Cross Site Scripting vulnerability in Omeka S v.4.2.0 allows a remote attacker to execute arbitrary code via the site navigation custom URL function
Affected Software
1 affected component
Omeka S=4.2.0
Event History
Aug 28, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Which deployments are identified as affected?
The provided information identifies Omeka S version 4.2.0 as affected.
2
What application feature is involved in exploitation?
The vulnerability is associated with the site navigation custom URL function.
3
Can the issue be exploited remotely?
Yes. The description states that a remote attacker can exploit the issue to execute arbitrary code.