
🚨*CVE* CVE-2026-18478 Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name of uploaded image,… https://www.cve.org/CVERecord?id=CVE-2026-18478 ----- Traducción: CVE-2026-18478 Mag… http://infoflow.cloud`
Post summary
The tweet announces the new CVE-2026-18478 affecting Magnolia CMS, detailing a stored XSS vulnerability that lets editors inject malicious code into image names, but it does not include PoC code, exploit tools, patches, or evidence of active exploitation.

