CVE-2026-25558

MEDIUM

QloApps 1.7.0 Stored XSS via SVG File Upload in Admin File Manager

Title source: cna
STIX 2.1

Description

QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through the file manager to execute arbitrary scripts in the browser of any user who subsequently views the file.

References (2)

Core 2
Core References
Exploit technical-description exploit
https://github.com/Qloapps/QloApps/issues/1728

Scores

CVSS v3 4.8
EPSS 0.0023
EPSS Percentile 13.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
QloApps/QloApps < 1.7.0
Published Jun 08, 2026
Tracked Since Jun 08, 2026