Stored XSS Vulnerability in WCMS by Vincent Peugnet
CVE-2026-105124
5.3MEDIUM
What is CVE-2026-105124?
The WCMS by Vincent Peugnet, up to version 3.18.0, contains a vulnerability that allows unauthenticated attackers to exploit stored cross-site scripting (XSS). By injecting scripts through the login user field and visitor comment fields, attackers can manipulate the admin log viewer and comment URLs in the edit right bar, potentially executing arbitrary scripts with elevated privileges. This vulnerability primarily affects the functionality around user inputs and their display, creating an avenue for malicious behavior if not properly mitigated.
Affected Version(s)
wcms 0 <= 3.18.0
