Reflected XSS Vulnerability in QloApps by QloApps
CVE-2026-89268
5.1MEDIUM
What is CVE-2026-89268?
The QloApps application, up to version 1.7.0, is susceptible to reflected Cross-Site Scripting (XSS) due to improper handling of back-office list filter POST parameters. This vulnerability allows attackers to craft malicious payloads, which can be submitted by authenticated users, leading to the execution of arbitrary JavaScript in their sessions. Consequently, this malicious script can read sensitive administrative data and perform unauthorized actions within the application, posing significant security risks to users.
Affected Version(s)
QloApps 0 <= 1.7.0
