VORANT. Threat Intelligence Sign in Get the full feed

Stored XSS Patched in Magnolia CMS

routine vulnerability technology

A stored XSS flaw in Magnolia CMS's import function let editors inject malicious HTML/JS via image filenames; fixed in version 6.3.10.

CERT Polska coordinated disclosure of CVE-2026-18478, a stored cross-site scripting vulnerability in Magnolia CMS's import functionality. An attacker holding editor privileges can embed arbitrary HTML and JavaScript into the name of an uploaded image; this payload executes when the image is subsequently opened or rendered within the CMS interface.

The vulnerability was responsibly reported by researchers Kacper Paluch and Łukasz Sobański and has been remediated in Magnolia CMS version 6.3.10. There is no indication of active exploitation in the wild; this is a coordinated disclosure advisory rather than a report of ongoing attack activity. Organizations running Magnolia CMS should update to the patched version to prevent privilege escalation via stored script execution against other authenticated users.

Mentioned in this report

Vulnerabilities CVE-2026-18478

Source reporting: https://cert.pl/en/posts/2026/08/CVE-2026-18478

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free