CVE-2026-105124

CVE-2026-105124 published: W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unes...

View full NVD advisory → ← Back to CVE watch