Sceawere

Vulnerability Detail

CVE-2026-105060UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Logo Showcase Stored XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
10h ago
Vendor
Themepoints
Product
Logo Showcase
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themepoints Logo Showcase logo-showcase allows Stored XSS.This issue affects Logo Showcase: from n/a through 4.0.4.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-10-05T09:17:10.863Z",
  "pubdate": "2026-10-05T09:17:10.863Z",
  "executiveSummary": "The Themepoints Logo Showcase plugin for WordPress is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability.\nThis vulnerability is categorized under CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').\nThe flaw allows unauthenticated or authenticated attackers to inject malicious JavaScript payloads into the application, which are subsequently stored within the database.\nWhen a user or administrator views the affected web page where the malicious content is rendered, the payload executes within the context of their session.\nThis poses significant risk, including unauthorized access to session cookies, session hijacking, defacement of the website, or unauthorized actions performed on behalf of the victim.\nThe vulnerability affects all versions of the Logo Showcase plugin ranging from n/a through 4.0.4.\nSuccessful exploitation requires the victim to access the manipulated component, and the impact depends on the privileges of the victim viewing the stored payload.",
  "technicalDetails": "The root cause of the Stored XSS vulnerability in Logo Showcase (versions n/a through 4.0.4) lies in the improper sanitization and validation of user-supplied input before it is persisted in the database and subsequently rendered in the front-end or administrative dashboard.\nIn a typical Stored XSS scenario, an attacker exploits input fields within the Logo Showcase interface that are processed by the server-side code without adequate escaping or filtering of HTML and JavaScript tags.\nThe attack flow begins when an attacker submits a crafted payload containing malicious script tags (e.g., <script>alert(document.cookie)</script>) through the plugin's configuration forms or input parameters.\nThe backend application receives this input and stores it directly into the database. Because the application fails to neutralize or encode this input upon output, the payload is served back to browsers in its raw, executable form whenever the affected logo display component is loaded.\nThe vulnerability is triggered when a user or administrator navigates to the page where the injected logo component is displayed. The web browser, interpreting the stored payload as legitimate script content, executes the malicious code within the Document Object Model (DOM) of the user's current browsing session.\nBecause the execution happens within the context of the user's session, the malicious script can access sensitive information such as session tokens, LocalStorage, and SessionStorage. Furthermore, the script can perform unauthorized requests to the server, modify page content, or redirect users to malicious external domains.\nThis vulnerability is particularly severe because the stored nature of the payload ensures it persists across multiple page refreshes and affects every visitor until the malicious input is manually purged from the database or the vulnerable component is patched.\nExploitation does not require advanced network-level access, as the injection occurs through standard application interfaces. The lack of context-aware output encoding ensures that any HTML attributes or body content populated by the plugin are susceptible to injection attacks, effectively bypassing standard browser-based XSS filters."
}
CVE-2026-105060: Logo Showcase Stored XSS (MEDIUM Severity, CVSS: 6.5) | Sceawere