# PluXml CMS patches three stored XSS flaws

Published: 2026-02-27 · Severity: medium
Canonical: https://vorant.io/reports/972b161e-4262-5d00-8664-d6117aa9e475/pluxml-cms-patches-three-stored-xss-flaws

> PluXml CMS versions 5.8.21 and 5.9.0-rc7 contain stored XSS and session fixation vulnerabilities that could let attackers hijack sessions or execute malicious scripts.

CERT Polska coordinated disclosure of three vulnerabilities in PluXml CMS. CVE-2026-24350 allows an authenticated attacker to upload a malicious SVG file that executes JavaScript when a victim views or directly accesses it. CVE-2026-24351 permits users with editing privileges to inject arbitrary HTML/JS into static pages, which executes when the page is visited. CVE-2026-24352 is a session fixation flaw where a session identifier can be set prior to authentication and remains unchanged afterward, allowing an attacker to fix a victim's session ID and later hijack the authenticated session.

The vendor was notified early in the disclosure process but did not respond with vulnerability details or confirm the affected version range. Only versions 5.8.21 and 5.9.0-rc7 were tested and confirmed vulnerable; other versions were not tested and may also be affected. No evidence of active exploitation was reported, and this appears to be a standard coordinated vulnerability disclosure rather than an ongoing attack campaign.

## Mentioned in this report

- Vulnerabilities: CVE-2026-24350, CVE-2026-24351, CVE-2026-24352

Source reporting: https://cert.pl/en/posts/2026/02/CVE-2026-24350

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/972b161e-4262-5d00-8664-d6117aa9e475/pluxml-cms-patches-three-stored-xss-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
