PT-2026-71229 · Craft Cms · Craft Cms

·

CVE-2026-72787

·

Published

2026-08-06

·

Updated

2026-08-12

CVSS v3.1

6.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Craft CMS versions prior to 5.10.8
Description A stored cross-site scripting issue exists in the control panel where draft names are rendered without HTML encoding in element chips and cards. This allows a low-privilege user with the ability to create element drafts to inject malicious JavaScript. The script executes in the browser of any higher-privileged user who views the affected element, potentially enabling unauthorized account creation and other authenticated actions.
Recommendations Update Craft CMS to version 5.10.8 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72787
GHSA-2RP4-X2J7-QMCC

Affected Products

Craft Cms