---
id: CVE-2026-105124
title: >-
  W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting
  vulnerability that allows unauthenticated attackers to inject scripts via the
  login user field and visitor comment website field
summary: >-
  W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting
  vulnerability that allows unauthenticated attackers to inject scripts via the
  login user field and visitor comment website field. Attackers can submit
  failed …
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: vincent-peugnet
product: wcms
affected:
  - wcms <= 3.18.0
published: '2026-10-04'
updated: '2026-10-04'
sourceUpdated: '2026-10-04T00:16:35.853'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105124'
references:
  - url: 'https://github.com/vincent-peugnet/wcms'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/class/Controllerconnect.php#L56
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/view/templates/adminlog.php#L71
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/vincent-peugnet/wcms/blob/cda5bcdb95dbdb1e804fdfe0e5fd2e2b2f8a90e2/app/view/templates/editrightbar.php#L110
    label: disclosure@vulncheck.com
  - url: 'https://github.com/vincent-peugnet/wcms/issues/662'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/w-wcms-through-3.18.0-unauthenticated-stored-xss-via-login-username-and-comments
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-03T23:50:15.753Z'
epss: 0.00215
epssPercentile: 0.10809
---

## Overview

W (vincent-peugnet/wcms) through 3.18.0 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject scripts via the login user field and visitor comment website field. Attackers can submit failed logins rendered unescaped in the adminlog.php log viewer, or comment URLs echoed into href attributes in editrightbar.php, executing script with administrator or editor privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
