CVE-2026-89268: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Webkul QloApps
CVE-2026-89268 is a cross-site scripting (XSS) vulnerability in Webkul QloApps versions up to 1.7.0. The issue arises because POST parameters used for back-office list filtering are rendered into HTML input value attributes without proper escaping. Authenticated attackers can exploit this by submitting crafted POST requests that execute arbitrary JavaScript in the victim's session, potentially allowing access to administrative data and unauthorized actions.
AI Analysis
Technical Summary
QloApps through version 1.7.0 improperly neutralizes input during web page generation in the back-office list helper template. Specifically, POST parameters for list filters are rendered into HTML input value attributes without escaping, enabling authenticated attackers to inject malicious JavaScript payloads via crafted POST requests. This results in cross-site scripting that executes in the context of the victim's session, potentially exposing administrative data and allowing unauthorized actions.
Potential Impact
The vulnerability allows authenticated attackers to execute arbitrary JavaScript in the context of an administrative user's session. This can lead to unauthorized reading of administrative data and performing actions with the victim's privileges. The CVSS 4.0 base score is 5.1, indicating a medium severity impact with network attack vector, low complexity, and requiring user interaction.
Mitigation Recommendations
No official patch or vendor advisory is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the back-office interface to trusted users only and consider implementing web application firewall (WAF) rules to detect and block suspicious POST requests targeting list filter parameters.
CVE-2026-89268: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Webkul QloApps
Description
CVE-2026-89268 is a cross-site scripting (XSS) vulnerability in Webkul QloApps versions up to 1.7.0. The issue arises because POST parameters used for back-office list filtering are rendered into HTML input value attributes without proper escaping. Authenticated attackers can exploit this by submitting crafted POST requests that execute arbitrary JavaScript in the victim's session, potentially allowing access to administrative data and unauthorized actions.
CVSS v4.0
Score 5.1medium
Affected software
Webkul
QloApps
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
QloApps through version 1.7.0 improperly neutralizes input during web page generation in the back-office list helper template. Specifically, POST parameters for list filters are rendered into HTML input value attributes without escaping, enabling authenticated attackers to inject malicious JavaScript payloads via crafted POST requests. This results in cross-site scripting that executes in the context of the victim's session, potentially exposing administrative data and allowing unauthorized actions.
Potential Impact
The vulnerability allows authenticated attackers to execute arbitrary JavaScript in the context of an administrative user's session. This can lead to unauthorized reading of administrative data and performing actions with the victim's privileges. The CVSS 4.0 base score is 5.1, indicating a medium severity impact with network attack vector, low complexity, and requiring user interaction.
Mitigation Recommendations
No official patch or vendor advisory is provided in the input data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the back-office interface to trusted users only and consider implementing web application firewall (WAF) rules to detect and block suspicious POST requests targeting list filter parameters.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-09-11T10:52:56.669Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa4b2a355bf5e2cf5bacd0e
Added to database: 09/12/2026, 02:02:11 UTC
Last enriched: 09/12/2026, 02:19:29 UTC
Last updated: 09/12/2026, 03:08:55 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.