PT-2026-76552 · Git+2 · Winter+1

·

CVE-2026-32257

·

Published

2026-08-12

·

Updated

2026-08-27

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Winter versions prior to 1.2.13
Description Custom CSS provided through the Brand Settings Styles field is compiled by the LESS parser and rendered without sanitization on every backend page. This allows a user with the backend.manage branding permission to perform a stored cross-site scripting attack against other backend users. To exploit this, an attacker must already possess trusted access to the backend with specific administrative permissions.
Recommendations Update to version 1.2.13. Restrict the backend.manage branding permission to only trusted administrators and developers.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32257
GHSA-V7CF-8GH9-GXMJ

Affected Products

Winter
Winter/Wn-Backend-Module