
CVE-2026-24351 PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into website, which wi… https://www.cve.org/CVERecord?id=CVE-2026-24351
Post summary
The text discloses that PluXml CMS has a stored XSS vulnerability in its static page editing feature, allowing attackers with edit privileges to inject arbitrary HTML and JavaScript; no exploitation evidence, PoC, or patch information is provided.


