PT-2026-51229 · Craft Cms · Craft Cms

·

CVE-2026-56381

·

Published

2026-03-11

·

Updated

2026-06-23

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Craft CMS versions 5.0.0-RC1 and later
Description A stored cross-site scripting issue exists in the User Permissions page. The software fails to properly perform HTML escaping when rendering user group names. This allows attackers with administrative privileges to inject arbitrary JavaScript through the user group name field, which then executes when other users view or edit permissions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56381
GHSA-9R7J-7JHG-4F4C
GHSA-G3HP-VVQF-8VW6

Affected Products

Craft Cms