VORANT. Threat Intelligence Sign in Get the full feed

PluXml CMS patches three stored XSS flaws

medium vulnerability

PluXml CMS versions 5.8.21 and 5.9.0-rc7 contain stored XSS and session fixation vulnerabilities that could let attackers hijack sessions or execute malicious scripts.

CERT Polska coordinated disclosure of three vulnerabilities in PluXml CMS. CVE-2026-24350 allows an authenticated attacker to upload a malicious SVG file that executes JavaScript when a victim views or directly accesses it. CVE-2026-24351 permits users with editing privileges to inject arbitrary HTML/JS into static pages, which executes when the page is visited. CVE-2026-24352 is a session fixation flaw where a session identifier can be set prior to authentication and remains unchanged afterward, allowing an attacker to fix a victim's session ID and later hijack the authenticated session.

The vendor was notified early in the disclosure process but did not respond with vulnerability details or confirm the affected version range. Only versions 5.8.21 and 5.9.0-rc7 were tested and confirmed vulnerable; other versions were not tested and may also be affected. No evidence of active exploitation was reported, and this appears to be a standard coordinated vulnerability disclosure rather than an ongoing attack campaign.

Mentioned in this report

Vulnerabilities CVE-2026-24350CVE-2026-24351CVE-2026-24352

Source reporting: https://cert.pl/en/posts/2026/02/CVE-2026-24350

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free