PT-2026-47296 · Qloapps · Qloapps

Vulncheck

·

Published

2026-06-08

·

Updated

2026-06-08

·

CVE-2026-25558

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through the file manager to execute arbitrary scripts in the browser of any user who subsequently views the file.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-25558

Affected Products

Qloapps