CVE-2026-25558
MEDIUM
NVD
CVSS Score
4.8
Severity
MEDIUM
Published
Jun 08, 2026
Vendor
unknown
Description
QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through the file manager to execute arbitrary scripts in the browser of any user who subsequently views the file.