Cross-site scripting in Craft CMS - #VU144275
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in another user\'s browser.
The vulnerability exists due to cross-site scripting in the site name field when rendering the site name in the control panel without escaping. A remote user can store a malicious script in the site name to execute arbitrary JavaScript in another user\'s browser.
The issue affects the control panel and requires allowAdminChanges to be enabled.