Magnolia · Magnolia Cms · CVE-2026-18478
**Name of the Vulnerable Software and Affected Versions**
Magnolia CMS versions prior to 6.3.10
**Description**
Stored Cross-Site Scripting (XSS) exists in the import functionality. An attacker with editor privileges can inject arbitrary HTML and JavaScript into the name of an uploaded image, which is then rendered and executed when the image is opened.
**Recommendations**
Update to version 6.3.10.