Stored XSS Patched in Magnolia CMS
A stored XSS flaw in Magnolia CMS's import function let editors inject malicious HTML/JS via image filenames; fixed in version 6.3.10.
CERT Polska coordinated disclosure of CVE-2026-18478, a stored cross-site scripting vulnerability in Magnolia CMS's import functionality. An attacker holding editor privileges can embed arbitrary HTML and JavaScript into the name of an uploaded image; this payload executes when the image is subsequently opened or rendered within the CMS interface.
The vulnerability was responsibly reported by researchers Kacper Paluch and Łukasz Sobański and has been remediated in Magnolia CMS version 6.3.10. There is no indication of active exploitation in the wild; this is a coordinated disclosure advisory rather than a report of ongoing attack activity. Organizations running Magnolia CMS should update to the patched version to prevent privilege escalation via stored script execution against other authenticated users.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/08/CVE-2026-18478
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free