Stored XSS Vulnerability in Sulu CMS by Sulu
CVE-2026-82396
5.4MEDIUM
What is CVE-2026-82396?
The Sulu content management system contains a stored XSS vulnerability in the MediaStreamController. Attackers with media upload rights can exploit this flaw by uploading malicious HTML, XHTML, or XML documents. When a victim accesses a crafted link with the inline query parameter enabled, the server returns the document with incorrect content disposition headers, allowing the execution of attacker-controlled JavaScript within the victim's session. This issue affects versions prior to 2.6.25 and 3.0.8 and can lead to unauthorized actions or data exposure.
Affected Version(s)
sulu < 2.6.25 < 2.6.25
sulu >= 3.0.0-alpha1, < 3.0.8 < 3.0.0-alpha1, 3.0.8
