CVE-2026-25558
QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrator
CVSS
4.8
Medio
EPSS
0.2%
p14
KEV
—
Exploit Today
4
0-100
Publicado: 8 jun 2026 · Última mod.: 23 jul 2026 · CWE-79
0.2%EPSS · 30 días0.2%
2026-07-272026-08-24
QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through the file manager to execute arbitrary scripts in the browser of any user who subsequently views the file.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-782827.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in Stripe Payments <= 2.1.2 versions.22hCVE-2026-782647.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in Toolset Blocks <= 1.6.26 versions.12hCVE-2026-782637.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in Event Tickets <= 5.29.2.1 versions.22hCVE-2026-325567.1 ALT—
——0Unauthenticated Cross Site Scripting (XSS) in Boost <= 2.0.4 versions.12hCVE-2026-715036.1 MED—
——0Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no Content-Security-Policy header is emitted. An unauthenticated attacker can cause an authenticated administrator to open a crafted URL to execute arbitrary JavaScript in that session and create a persistent administrator account.1dCVE-2026-308648.9 ALT—
——0Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.1d