PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page.
The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only versions 5.8.21 and 5.9.0-rc7 were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://cert.pl/posts/2026/03/CVE-2026-24350 |
|
| https://pluxml.org/ |
|
History
Fri, 27 Feb 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page. The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only versions 5.8.21 and 5.9.0-rc7 were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable. | |
| Title | Stored XSS in PluXml CMS | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-02-27T11:35:23.141Z
Reserved: 2026-01-22T14:08:35.743Z
Link: CVE-2026-24351
No data.
Status : Received
Published: 2026-02-27T12:16:03.047
Modified: 2026-02-27T12:16:03.047
Link: CVE-2026-24351
No data.
OpenCVE Enrichment
No data.