Qt Group PlcCVE-2026-15037
Improper output neutralization
Low2.9CVE-2026-15037 · Published Jul 23, 2026
Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Qt Product | >= 4.0.0, < 6.12.0 | 6.12.0 |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-91
More Qt Group Plc advisories
All Qt Group Plc| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 16 | qt: denial of service | High7.1 | No fix yet |
| Sep 11 | qt: out-of-bounds read | Medium6.9 | 6.8.9+1 more |
| Sep 8 | qt: denial of service | High7.1 | 6.8.2 |
| Jul 21 | Qt: out-of-bounds read | Medium6.3 | 6.8.8+2 more |
| Jul 16 | Qt Group Plc Axivion: open redirect | Medium6.8 | No fix yet |
| Jul 9 | Qt Group Plc Axivion: missing authorization | High8.7 | 7.9.13+2 more |