Cross-site scripting in Craft CMS - #VU144275

 

Cross-site scripting in Craft CMS - #VU144275

Published: August 19, 2026


Vulnerability identifier: #VU144275
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: N/A
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary JavaScript in another user\'s browser.

The vulnerability exists due to cross-site scripting in the site name field when rendering the site name in the control panel without escaping. A remote user can store a malicious script in the site name to execute arbitrary JavaScript in another user\'s browser.

The issue affects the control panel and requires allowAdminChanges to be enabled.


Affected software

Craft CMS

Remediation

Install security update from vendor's website.

Craft CMS - update to 5.10.11

External References

Related Security Bulletins