CVE-2026-18478: Magnolia Dxp Magnolia CMS
Medium severity, CVSS 5.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image, which will be rendered/executed when opening uploaded image. The issue was fixed in version 6.3.10
Affected products
- Magnolia Dxp Magnolia CMS: from 6.3.0, before 6.3.10 (fixed in 6.3.10)
Published 2026-08-10. Last modified 2026-08-28.