PT-2026-76553 · Git+2 · Winter+1

·

CVE-2026-32258

·

Published

2026-08-12

·

Updated

2026-08-27

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Winter versions 1.2.10 through 1.2.12
Description Authenticated backend users with the backend.manage editor permission can store custom Markup Styles via Settings → Editor Settings → Markup Styles. These styles are compiled by the LESS parser and rendered on every backend page without sanitization, enabling stored cross-site scripting (XSS). The issue occurs within the renderCss() function, which failed to sanitize the compiled CSS output.
Recommendations Update Winter versions 1.2.10 through 1.2.12 to version 1.2.13. Restrict the backend.manage editor permission to trusted administrators and developers only.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32258
GHSA-VGP4-2FC4-QFF2

Affected Products

Winter
Winter/Wn-Backend-Module