CVE-2026-38948: XSS
Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properly sanitize uploaded SVG files, allowing a low-privileged authenticated user to upload a crafted SVG file containing malicious code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-38948?
CVE-2026-38948 has a medium severity score of 5.4 according to the CVSS v3.1 metrics.
How do I fix CVE-2026-38948?
To fix CVE-2026-38948, update FUEL CMS to version 1.5.3 or later where the SVG upload sanitization issues are resolved.
What type of vulnerability is CVE-2026-38948?
CVE-2026-38948 is classified as a Cross-Site Scripting (XSS) vulnerability.
Who is affected by CVE-2026-38948?
CVE-2026-38948 affects users of FUEL CMS v1.5.2 and prior, specifically those with low-privileged authenticated access.
What is the impact of CVE-2026-38948?
The impact of CVE-2026-38948 allows an attacker to inject malicious code through improperly sanitized SVG files uploaded by authenticated users.