CVE-2026-14856
Last modified
CVE-2026-14856 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization of SVG files. An authenticated user with low privileges can upload a malicious SVG file containing JavaScript code.
Description
A stored Cross-Site Scripting (XSS) vulnerability in the file upload functionality of the Media Manager in TastyIgniter v4.3.0, caused by insufficient validation and sanitization of SVG files. An authenticated user with low privileges can upload a malicious SVG file containing JavaScript code. When an administrator views that file, the code executes in the context of their browser. By chaining this vulnerability with a Cross-Site Request Forgery (CSRF) attack, an attacker can extract the administrator’s CSRF token and perform unauthorized actions—such as modifying credentials—thereby gaining full control of the administrative account.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Media Manager | TastyIgniter | 4.3.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-14856?
How severe is CVE-2026-14856?
How do I fix CVE-2026-14856?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-14849The Paid Membership Subscriptions WordPress plugin before 3…3.7
- CVE-2026-1485A flaw was found in Glib's content type parsing logic. This …2.8
- CVE-2026-14850The password reset funcionality is vulnerable to unauthorize…8.8
- CVE-2026-14852Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p…5.2
- CVE-2026-14853The WooCommerce Bookings WordPress plugin before 3.9.0 does …4.3
- CVE-2026-14855The RT Mega Menu plugin for WordPress is vulnerable to Store…6.4
- CVE-2026-14857The WP Crowdfunding WordPress plugin before 2.2.1 does not v…4.3
- CVE-2026-14858The WP Crowdfunding WordPress plugin before 2.2.1 does not v…4.3
- CVE-2026-14859The WP Crowdfunding WordPress plugin before 2.2.1 does not c…4.3
- CVE-2026-1486A flaw was found in Keycloak. A vulnerability exists in the …8.8
- CVE-2026-14860The Podcast Player WordPress plugin before 8.3.1 does not v…5.3
- CVE-2026-14861The User Verification by PickPlugins WordPress plugin throug…7.5
Are you affected by CVE-2026-14856?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
