CVE-2026-89268
MEDIUMCVSS 5.4Description
QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to read administrative data and perform actions.
Timeline
Published:September 12th, 2026 2:16 AM
Last modified:September 14th, 2026 7:17 PM
CVSS Scoring
CVSS v3: 5.4 (MEDIUM)
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Weaknesses (CWE)
References & Reports
Advisories, patches, and third-party reports
- https://github.com/Qloapps/QloApps
- https://github.com/Qloapps/QloApps/blob/v1.7.0/admin/themes/default/template/helpers/list/list_header.tpl
- https://github.com/Qloapps/QloApps/commit/153ec1c8567798bd99155098ecc0a340e38f25bf
- https://github.com/Qloapps/QloApps/pull/1801
- https://www.vulncheck.com/advisories/qloapps-through-1.7.0-reflected-xss-via-list-filter-parameters
Source: NIST NVD · Data may lag official sources by up to one minute