Junglewise Threat Intelligence

CVE-2026-18957: Menulux Portal stored cross-site scripting

CVE-2026-18957 · Severity: medium · CVSS 5.4 · Published 2026-09-04

Technologies: Menulux Software Inc. Menulux Portal. Vendors: Menulux Software Inc..

Executive brief

Menulux Portal is a web-based application used for menu management and portal functionality. This vulnerability allows attackers to inject malicious JavaScript code that persists in the application and executes in users' browsers, potentially compromising user sessions, stealing credentials, or defacing content viewed by other portal users.

Technical details

This is a stored cross-site scripting (XSS) vulnerability arising from improper neutralization of user-supplied input during web page generation. The vulnerability exists in Menulux Portal before version 20260903211448. Attackers can inject malicious JavaScript through user-controlled input fields that are stored in the application and later rendered to other users without proper sanitization or encoding. No special authentication or network preconditions have been disclosed. A successful exploit allows arbitrary JavaScript execution in the context of affected users' browsers, enabling session hijacking, credential theft, or malware distribution. A patched version addressing this issue has been released.

Affected products

  • Menulux Software Inc. Menulux Portal before 20260903211448

Timeline

  • 2026-09-04: disclosed
  • 2026-09-03: patched: Version 20260903211448 and later

References

Related threats