CVE-2026-89268: QloApps through 1.7.0 Reflected XSS via List Filter Parameters

Published Sep 12, 2026
·
Updated

QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to read administrative data and perform actions.

Affected Software

1 affected component
QloApps<=1.7.0

Event History

Sep 12, 2026
CVE Published
via MITRE·01:50 AM
Data Sourced
via MITRE·01:50 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Authenticated back-office users who can be induced to submit a crafted POST request to a list controller are exposed. Successful exploitation runs JavaScript in the victim's authenticated session.

2

What access and interaction does an attacker need?

The attacker needs low-level privileges and must persuade an authenticated user to submit a malicious POST request containing crafted list-filter parameters. The vulnerability is network-reachable and has low attack complexity.

3

What could successful exploitation allow?

JavaScript executing in the victim's session can read administrative data and perform actions with that user's permissions. The stated impact includes low confidentiality and integrity impact, with no availability impact.

4

Which versions are affected?

QloApps through version 1.7.0 is affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203