CVE-2026-14856

MEDIUM

Stored Cross-Site Scripting (XSS) in TastyIgniter Media Manager

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-14856. PoCs published by jonas-fernandez-as.

AI-analyzed exploit summary The repository claims to detail a stored XSS to account takeover vulnerability in TastyIgniter v4.3.0 (CVE-2026-14856) but does not include exploit code or technical breakdown. Instead, it references an external PDF for the 'full technical report,' which is a common social engineering tactic to lure researchers into downloading files from untrusted sources.

Description

A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization of SVG files. An authenticated user with low privileges can upload a malicious SVG file containing JavaScript code. When an administrator views that file, the code executes in the context of their browser. By chaining this vulnerability with a Cross-Site Request Forgery (CSRF) attack, an attacker can extract the administrator’s CSRF token and perform unauthorized actions—such as modifying credentials—thereby gaining full control of the administrative account.

Exploits (1)

github SUSPICIOUS
by jonas-fernandez-as · poc
https://github.com/jonas-fernandez-as/CVE-2026-14856-TastyIgniter

The repository claims to detail a stored XSS to account takeover vulnerability in TastyIgniter v4.3.0 (CVE-2026-14856) but does not include exploit code or technical breakdown. Instead, it references an external PDF for the 'full technical report,' which is a common social engineering tactic to lure researchers into downloading files from untrusted sources.

Classification
Suspicious 95%
Attack Type
Xss
Complexity
Moderate
Reliability
Reliable
Target: TastyIgniter v4.3.0
Auth required
Prerequisites: Authenticated low-privilege user access · Administrator interaction (viewing the malicious SVG file)
mistral-large-3 · analyzed Jul 28, 2026 Full analysis →

Scores

CVSS v4 6.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
Media Manager/TastyIgniter 4.3.0
Published Jul 27, 2026
Tracked Since Jul 27, 2026