Cross-site scripting in Craft CMS - #VU139972
Published: July 29, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in a higher-privileged user's control-panel session.
The vulnerability exists due to cross-site scripting in the control-panel helper that renders element chip/card labels when rendering an element's draft name without HTML encoding. A remote user can create a draft with a crafted draft name to execute arbitrary JavaScript in a higher-privileged user's control-panel session.
User interaction is required because a higher-privileged control-panel user must be shown the affected element's chip or card in the control panel.