What is CVE-2026-14856?
CVE-2026-14856 is a stored XSS vulnerability in the Media Manager's file upload feature of TastyIgniter v4.3.0, due to insufficient SVG validation. An authenticated low-privileged user can upload a malicious SVG with JavaScript, which executes in the browsers of users who view the file.
Azərbaycanca: CVE-2026-14856, TastyIgniter v4.3.0 platformasının Media Manager bölməsində aşkarlanmış stored XSS zəifliyidir. SVG fayllarının yetərsiz yoxlanılması səbəbindən, autentifikasiya olunmuş aşağı səlahiyyətli istifadəçi zərərli JavaScript kodu yükləyə bilər. Bu fayla baxan hər hansı istifadəçinin brauzerində kod icra oluna bilər.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What privileges are required for an attacker to exploit CVE-2026-14856?
The attacker must be an authenticated low-privileged user on the TastyIgniter v4.3.0 platform.
What is the root cause of the CVE-2026-14856 stored XSS vulnerability?
Insufficient validation of SVG files in the Media Manager section of TastyIgniter v4.3.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.