← Vulnerability feed

Vulnerability record · CVE-2026-35169 · published 8 April 2026

CVE-2026-35169: Mcgill loris cross-site scripting vulnerability

Mcgill · Loris

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From to before 27.0.3 and 28.0.1, the help_editor module of LORIS did not properly sanitize some user supplied variables which could result in a reflected cross-site scripting attack if a user is tricked into following an invalid link. The same input vector could also allow an attacker to download arbitrary markdown files on an unpatched server. This vulnerability is fixed in 27.0.3 and 28.0.1.

5.4 CVSS 3.1 Medium EPSS 0.27% · top 82.3% CWE-79 · Cross-site scriptingCWE-552 · CWE-552
5.4CVSS 3.1 base score
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
24 Jul 2026Last modified by NVD

Description

LORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging research. From to before 27.0.3 and 28.0.1, the help_editor module of LORIS did not properly sanitize some user supplied variables which could result in a reflected cross-site scripting attack if a user is tricked into following an invalid link. The same input vector could also allow an attacker to download arbitrary markdown files on an unpatched server. This vulnerability is fixed in 27.0.3 and 28.0.1.

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-35169 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-26984Mcgill loris path traversal vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 1.1%8.6CVE-2026-35446Mcgill loris vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.38%7.5CVE-2026-33350Mcgill loris sql injection vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.41%7.5CVE-2026-34392Mcgill loris vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.42%6.5CVE-2026-34985Mcgill loris insecure direct object reference vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.27%6.5CVE-2026-35165Mcgill loris insecure direct object reference vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.27%6.5CVE-2026-26985Mcgill loris path traversal vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.52%6.1CVE-2026-39985Mcgill loris open redirect vulnerabilityLORIS (Longitudinal Online Research and Imaging System) is a self-hosted web application that provides data- and project-management for neuroimaging …EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2026-35169), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.