PT-2026-78655 · Git+1 · Pkp-Lib

·

CVE-2026-76572

·

Published

2026-08-19

·

Updated

2026-08-19

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions pkp pkp-lib versions prior to 3.3.0-23 pkp pkp-lib versions prior to 3.4.0-11 pkp pkp-lib versions prior to 3.5.0-5
Description A remote attack is possible through the manipulation of the transformPHP() function within the classes/xslt/XSLTransformer.php file. This issue leads to an XML External Entity (XXE) reference, which occurs when an application processes XML input containing a reference to an external entity.
Recommendations Update to version 3.3.0-23. Update to version 3.4.0-11. Update to version 3.5.0-5. As a temporary mitigation, restrict access to the transformPHP() function.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76572

Affected Products

Pkp-Lib