Medium severity5.4NVD Advisory· Published Feb 27, 2026· Updated May 19, 2026
CVE-2026-24351
CVE-2026-24351
Description
PluXml CMS is vulnerable to Stored XSS in Static Pages editing functionality. Attacker with editing privileges can inject arbitrary HTML and JS into website, which will be rendered/executed when visiting edited page.
The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only versions 5.8.21 and 5.9.0-rc7 were tested and confirmed as vulnerable, other versions were not tested and might also be vulnerable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4Patches
Vulnerability mechanics
References
2- cert.pl/posts/2026/03/CVE-2026-24350nvdBroken Link
- pluxml.orgnvdProduct
News mentions
0No linked articles in our index yet.