PT-2026-47296 · Qloapps · Qloapps

·

CVE-2026-25558

·

Published

2026-06-08

·

Updated

2026-06-08

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions QloApps versions prior to 1.7.1
Description A stored cross-site scripting issue exists in the admin file manager. Authenticated administrators can inject malicious JavaScript by uploading specially crafted SVG files. By embedding JavaScript event handlers, such as onload, within these files, arbitrary scripts can be executed in the browser of any user who views the uploaded file.
Recommendations Update to a version later than 1.7.0. As a temporary mitigation, restrict the ability to upload SVG files through the admin file manager.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-25558

Affected Products

Qloapps