Stored XSS Vulnerability in Sulu CMS by Sulu
CVE-2026-82396

5.4MEDIUM

Key Information:

Vendor

Sulu

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82396?

The Sulu content management system contains a stored XSS vulnerability in the MediaStreamController. Attackers with media upload rights can exploit this flaw by uploading malicious HTML, XHTML, or XML documents. When a victim accesses a crafted link with the inline query parameter enabled, the server returns the document with incorrect content disposition headers, allowing the execution of attacker-controlled JavaScript within the victim's session. This issue affects versions prior to 2.6.25 and 3.0.8 and can lead to unauthorized actions or data exposure.

Affected Version(s)

sulu < 2.6.25 < 2.6.25

sulu >= 3.0.0-alpha1, < 3.0.8 < 3.0.0-alpha1, 3.0.8

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.