CVE-2026-25558

Source
https://cve.org/CVERecord?id=CVE-2026-25558
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25558.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-25558
Published
2026-06-08T14:01:25.022Z
Modified
2026-08-12T03:51:15.421968042Z
Severity
  • 4.8 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
QloApps 1.7.0 Stored XSS via SVG File Upload in Admin File Manager
Details

QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through the file manager to execute arbitrary scripts in the browser of any user who subsequently views the file.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25558.json"
}
References

Affected packages

Git / github.com/qloapps/qloapps

Affected ranges

Type
GIT
Repo
https://github.com/qloapps/qloapps
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.7.0"
        },
        {
            "fixed": "1.7.0"
        }
    ]
}

Affected versions

v0.*
v0.3
v1.*
v1.3.0
v1.3.1
v1.3.2
v1.4.0
v1.4.1
v1.5.0
v1.5.2
v1.6.0
v1.6.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25558.json"