Description
W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges.
Published: 2026-10-03
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 03 Oct 2026 23:30:00 +0000

Type Values Removed Values Added
Description W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges.
Title W (wcms) through 3.18.0 Unauthenticated Stored XSS via Login Username and Comments
First Time appeared Wcms
Wcms wcms
Weaknesses CWE-79
CPEs cpe:2.3:a:wcms:wcms:*:*:*:*:*:*:*:*
Vendors & Products Wcms
Wcms wcms
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-03T22:30:13.022Z

Reserved: 2026-10-03T12:05:26.755Z

Link: CVE-2026-105124

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-04T00:16:35.853

Modified: 2026-10-04T00:16:35.853

Link: CVE-2026-105124

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-04T01:00:07Z

Weaknesses