What is CVE-2026-8166?
This is a Stored Cross-Site Scripting (XSS) vulnerability discovered in the E-Logo Purchasing Portal by Logo Software. Based on the provided information, versions prior to 1.52 are affected, potentially allowing malicious scripts to be executed in users' browsers. It is strongly recommended to update the portal to the latest version immediately.
Azərbaycanca: Bu, Logo Software şirkətinin E-Logo Satınalma Portalında aşkarlanmış Saxlanılan XSS (Stored Cross-Site Scripting) zəifliyidir. Təqdim olunan məlumata əsasən, versiya 1.52-dən əvvəlki versiyalar təsirlənir, bu da zərərli skriptlərin səhifədə icra olunmasına imkan verir. Portalı dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the E-Logo Purchasing Portal are affected by CVE-2026-8166?
Based on the available information, versions of Logo Software's E-Logo Purchasing Portal prior to 1.52 are affected by this Stored XSS vulnerability.
What action is recommended to mitigate CVE-2026-8166?
Based on the provided information, it is strongly recommended to update the E-Logo Purchasing Portal to the latest version immediately to mitigate this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.