MEDIUM
Magnolia
CVE published 2026-08-10
CVE-2026-18478
CVE-2026-18478 is a Stored XSS vulnerability in Magnolia CMS import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into image names, executed when images are opened. The issue was fixed in version 6.3.10. This vulnerability affects Magnolia CMS users with editor privileges, allowing for arbitrary code execution on the client-side when an image with maliciously crafted n [truncated]