MPSA-2026-001: Stored cross-site scripting in user and resource name fields
-
MultiPortal has published security advisory MPSA-2026-001, a stored cross-site scripting issue in user and resource name fields.
- Severity: High (CVSS v3.1 base 8.7)
- Affected: MultiPortal Core 1.1.2, 1.1.3, and 1.2.0
- Fixed in: 1.2.1
If you run an affected version, upgrade to 1.2.1 at your next maintenance window. The fix needs no data cleanup: existing names are made safe when they are displayed.
Read the full advisory, including impact, remediation, and workaround:
MPSA-2026-001 on docs.multiportal.ioThe fix ships in the 1.2.1 release. To report a vulnerability privately, see Reporting security issues.
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login