Cross-site scripting in Craft CMS - CVE-2022-28378
Published: April 4, 2022 / Updated: April 17, 2026
Craft CMS
Pixel & Tonic, Inc.
Description
The vulnerability allows a remote attacker to execute arbitrary script code in a victim's browser.
The vulnerability exists due to cross-site scripting in the Feeds widget on the dashboard when processing a malformed feed. A remote attacker can supply a specially crafted feed to execute arbitrary script code in a victim's browser.