Stored XSS Vulnerability in WCMS by Vincent Peugnet
CVE-2026-105124

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
3 October 2026

What is CVE-2026-105124?

The WCMS by Vincent Peugnet, up to version 3.18.0, contains a vulnerability that allows unauthenticated attackers to exploit stored cross-site scripting (XSS). By injecting scripts through the login user field and visitor comment fields, attackers can manipulate the admin log viewer and comment URLs in the edit right bar, potentially executing arbitrary scripts with elevated privileges. This vulnerability primarily affects the functionality around user inputs and their display, creating an avenue for malicious behavior if not properly mitigated.

Affected Version(s)

wcms 0 <= 3.18.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ikram-4
.