PT-2026-84666 · Craft Cms · Craft Cms

·

CVE-2026-84793

·

Published

2026-09-02

·

Updated

2026-09-02

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Craft CMS versions 5.0.0-RC1 through 5.10.10
Description A stored cross-site scripting issue exists due to improper sanitization of input in the site name field. This allows administrators to inject arbitrary JavaScript payloads that execute when other users access the control panel settings pages.
Recommendations Update Craft CMS to version 5.10.11.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84793
GHSA-5FJJ-496J-2QQF

Affected Products

Craft Cms