CVE-2026-15037: Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized b
Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-15037
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-150370.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-15037 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] QT: Vulnerability allows file manipulationcert-bund
Recent advisories for Improper output neutralization
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-49099: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injecti…nvd · 2026-07-06
- mediumCVE-2026-49098: Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Dow…nvd · 2026-07-06
- mediumCVE-2026-49097: Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Dow…nvd · 2026-07-06
- criticalCVE-2026-48203: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injecti…nvd · 2026-07-06
- highCVE-2026-49091: Improper Output Neutralization for Logs (CWE-117) in Kibana can lead to log injection via Log …nvd · 2026-07-01
- unknownCVE-2026-54889: Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp m…nvd · 2026-06-29
More from NVD Recent CVEs
- unknownCVE-2026-18556: Authentication bypass using an alternate path or channel vulnerability in N-able N-central all…2026-08-01
- unknownCVE-2026-55735: Improper Verification of Cryptographic Signature in ueberauth guardian allows an unauthenticat…2026-08-01
- unknownCVE-2026-55734: Allocation of Resources Without Limits or Throttling vulnerability in ueberauth guardian (Guar…2026-08-01
- unknownCVE-2026-55733: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01
- unknownCVE-2026-54894: Allocation of Resources Without Limits or Throttling in ueberauth guardian allows denial of se…2026-08-01