Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 12 Sep 2026 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to read administrative data and perform actions. | |
| Title | QloApps through 1.7.0 Reflected XSS via List Filter Parameters | |
| First Time appeared |
Webkul
Webkul qloapps |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Webkul
Webkul qloapps |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-12T01:50:33.852Z
Reserved: 2026-09-11T10:52:56.669Z
Link: CVE-2026-89268
No data.
Status : Received
Published: 2026-09-12T02:16:24.623
Modified: 2026-09-12T02:16:24.623
Link: CVE-2026-89268
No data.
OpenCVE Enrichment
Updated: 2026-09-12T09:00:06Z
