CVE-2026-8166: Stored XSS in Logo Software's e-Logo Purchasing Portal
Published Aug 6, 2026
·Updated
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Purchasing Portal allows Stored XSS.
This issue affects e-Logo Purchasing Portal: before 1.52.
Affected Software
1 affected component
Logo Software Industry and Trade Inc. e-Logo Purchasing Portal<1.52
Event History
Aug 6, 2026
CVE Published
via MITRE·11:30 AM
Data Sourced
via MITRE·11:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-8166?
CVE-2026-8166 has a medium severity rating of 5.4.
2
How do I fix CVE-2026-8166?
To fix CVE-2026-8166, update the e-Logo Purchasing Portal to version 1.52 or later.
3
What type of vulnerability is CVE-2026-8166?
CVE-2026-8166 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
4
What impact does CVE-2026-8166 have on users?
CVE-2026-8166 can allow attackers to execute malicious scripts in the context of the user's session.
5
Who is affected by CVE-2026-8166?
CVE-2026-8166 affects users of the Logo Software Industry and Trade Inc. e-Logo Purchasing Portal prior to version 1.52.