CVE-2026-25558

QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through the file manager to execute arbitrary scripts in the browser of any user who subsequently views the file.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-08 15:16

Updated : 2026-07-23 07:10


NVD link : CVE-2026-25558

Mitre link : CVE-2026-25558

CVE.ORG link : CVE-2026-25558


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')