PT-2026-71229 · Craft Cms · Craft Cms
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Craft CMS versions prior to 5.10.8
Description
A stored cross-site scripting issue exists in the control panel where draft names are rendered without HTML encoding in element chips and cards. This allows a low-privilege user with the ability to create element drafts to inject malicious JavaScript. The script executes in the browser of any higher-privileged user who views the affected element, potentially enabling unauthorized account creation and other authenticated actions.
Recommendations
Update Craft CMS to version 5.10.8 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Craft Cms