Junglewise Threat Intelligence

CVE-2026-18478: Magnolia CMS stored XSS in image import functionality

CVE-2026-18478 · Severity: info · CVSS 0 · Published 2026-08-10

Technologies: Magnolia CMS.

Executive brief

Magnolia CMS is a digital experience platform used to build and manage websites and content. An attacker with editor-level access can inject malicious code into image file names during upload, which executes in a browser when the image is viewed, potentially compromising the accounts of administrators and other users who access that content.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in the image import functionality, where input validation is missing when processing the name field of uploaded images. An attacker with editor privileges can inject arbitrary HTML and JavaScript into the image name, which is rendered without proper sanitization when the image is subsequently opened or viewed. The vulnerability affects Magnolia CMS versions 6.3.0 through 6.3.9; it was fixed in version 6.3.10. The attack requires authenticated access with editor-level permissions and no user interaction beyond viewing the uploaded image.

Affected products

  • Magnolia CMS 6.3.0 to 6.3.9

Timeline

  • 2026-08-10: disclosed
  • 2025-06-26: patched: Fixed in version 6.3.10 (LTS release date June 26, 2025)

References