CVE WATCH / VULNERABILITY DETAIL
CVE-2026-105124
MEDIUMCVSS 6.1NVD feed
Published 4 October 2026 · tracked since 4 October 2026
Description
W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or co
References
- NVD — National Vulnerability Database
- CVE.org record (MITRE)
- CISA Known Exploited Vulnerabilities catalog
Latest tracked vulnerabilities
- CVE-2026-105123 HIGH 8.8
- CVE-2026-105125 LOW 3.7
- CVE-2026-105118 MEDIUM 4.7
- CVE-2026-97873
- CVE-2026-71889
- CVE-2026-71891
- CVE-2026-71885
- CVE-2026-71886
- CVE-2026-92767 MEDIUM 6.4
- CVE-2026-92084 CRITICAL 9.1