CVE-2026-24351Disclosure(pluxml / pluxml)

LOWCVSS 5.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only versions 5.8.21 and 5.9.0-rc7 were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pluxml

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
pluxml

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-27: 3Technical Details · 2026-02-27: 302-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-24351 PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into website, which wi… https://www.cve.org/CVERecord?id=CVE-2026-24351

    Post summary

    The text discloses that PluXml CMS has a stored XSS vulnerability in its static page editing feature, allowing attackers with edit privileges to inject arbitrary HTML and JavaScript; no exploitation evidence, PoC, or patch information is provided.

    0000078
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24351 Stored XSS Vulnerability in PluXml CMS Static Pages Editing Functionality https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24351

    Post summary

    This post announces a stored XSS vulnerability in PluXml CMS’s static page editing, with no PoC, exploitation, patch, or false‑positive claim provided.

    0000029
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-24351 - Stored XSS in PluXml CMS Intel Report: https://ift.tt/ogsultj

    Post summary

    A stored XSS vulnerability (CVE-2026-24351) in PluXml CMS has been disclosed, with an Intel report linked for further details.

    000003
    341 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Apppluxmlpluxml5.8.21--
Apppluxmlpluxml5.9.0--

Explore more