PT-2026-7835 · Wix · Wix
Published
2026-02-12
·
Updated
2026-05-18
·
CVE-2026-2276
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Wix (affected versions not specified)
Description
A Reflected Cross-Site Scripting (XSS) issue exists in the Wix web application. The vulnerability is located in the SVG image upload functionality at the ''https://manage.wix.com/account/account-settings'' endpoint, which does not adequately sanitize uploaded content. An authenticated attacker can upload a malicious SVG file containing embedded JavaScript code. This code is then stored and executed when other users view the image, potentially allowing arbitrary code execution in the victim's browser. This could result in the disclosure of sensitive information or session hijacking. The vulnerable parameter is the SVG file content itself.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wix