PT-2026-7835 · Wix · Wix

Published

2026-02-12

·

Updated

2026-05-18

·

CVE-2026-2276

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Wix (affected versions not specified)
Description A Reflected Cross-Site Scripting (XSS) issue exists in the Wix web application. The vulnerability is located in the SVG image upload functionality at the ''https://manage.wix.com/account/account-settings'' endpoint, which does not adequately sanitize uploaded content. An authenticated attacker can upload a malicious SVG file containing embedded JavaScript code. This code is then stored and executed when other users view the image, potentially allowing arbitrary code execution in the victim's browser. This could result in the disclosure of sensitive information or session hijacking. The vulnerable parameter is the SVG file content itself.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-2276

Affected Products

Wix