Description
QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to read administrative data and perform actions.
Published: 2026-09-12
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

QloApps up to version 1.7.0 contains a reflected cross‑site scripting flaw because back‑office list filter POST parameters are rendered without escaping into HTML input value attributes. An attacker who can convince an authenticated administrator to submit a crafted POST request to a list controller can inject arbitrary JavaScript that executes within the victim’s session. This allows reading sensitive administrative information, manipulating tasks or hijacking the session. The weakness aligns with CWE‑79.

Affected Systems

The affected software is the QloApps e‑commerce platform developed by Webkul; every release up to and including version 1.7.0 is vulnerable. No further sub‑version at or before 1.7.0 are considered at risk.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity, and the exploit requires a legitimate administrator to be authenticated and to submit a malicious POST request. The EPSS score of less than 1 % points to a low probability of exploitation at the current time. The flaw is not listed in CISA’s KEV catalog, suggesting that widespread attacks have not yet been detected. However, because the vulnerability’s exploited code runs with administrative privileges, it presents a notable risk to the confidentiality, integrity, and availability of back‑office data and functions.

Generated by OpenCVE AI on September 15, 2026 at 19:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade QloApps to a release newer than 1.7.0 if available; check the vendor’s latest version for the fixed template.
  • If upgrading is not immediately possible, edit the file admin/themes/default/template/helpers/list/list_header.tpl to escape all POST parameters before inserting them into HTML value attributes.
  • Implement input validation or a web non‑numeric list from being processed.

Generated by OpenCVE AI on September 15, 2026 at 19:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 12 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description QloApps through 1.7.0 renders back-office list filter POST parameters into HTML input value attributes without escaping them in the list helper template. Attackers can induce authenticated users to submit crafted POST requests with malicious payloads to list controllers, executing arbitrary JavaScript in the victim's session to read administrative data and perform actions.
Title QloApps through 1.7.0 Reflected XSS via List Filter Parameters
First Time appeared Webkul
Webkul qloapps
Weaknesses CWE-79
CPEs cpe:2.3:a:webkul:qloapps:*:*:*:*:*:*:*:*
Vendors & Products Webkul
Webkul qloapps
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T18:33:56.410Z

Reserved: 2026-09-11T10:52:56.669Z

Link: CVE-2026-89268

cve-icon Vulnrichment

Updated: 2026-09-14T18:33:52.953Z

cve-icon NVD

Status : Deferred

Published: 2026-09-12T02:16:24.623

Modified: 2026-09-23T17:17:47.327

Link: CVE-2026-89268

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:15:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')