# Stored XSS Patched in Magnolia CMS

Published: 2026-08-10 · Severity: routine · Sectors: technology
Canonical: https://vorant.io/reports/225e27d7-6d66-5775-8629-c84ffb16829c/stored-xss-patched-in-magnolia-cms

> A stored XSS flaw in Magnolia CMS's import function let editors inject malicious HTML/JS via image filenames; fixed in version 6.3.10.

CERT Polska coordinated disclosure of CVE-2026-18478, a stored cross-site scripting vulnerability in Magnolia CMS's import functionality. An attacker holding editor privileges can embed arbitrary HTML and JavaScript into the name of an uploaded image; this payload executes when the image is subsequently opened or rendered within the CMS interface.

The vulnerability was responsibly reported by researchers Kacper Paluch and Łukasz Sobański and has been remediated in Magnolia CMS version 6.3.10. There is no indication of active exploitation in the wild; this is a coordinated disclosure advisory rather than a report of ongoing attack activity. Organizations running Magnolia CMS should update to the patched version to prevent privilege escalation via stored script execution against other authenticated users.

## Mentioned in this report

- Vulnerabilities: CVE-2026-18478

Source reporting: https://cert.pl/en/posts/2026/08/CVE-2026-18478

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/225e27d7-6d66-5775-8629-c84ffb16829c/stored-xss-patched-in-magnolia-cms.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
