Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xh8r-pv2v-rc22

Опубликовано: 12 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.1
CVSS3: 6.4

Описание

Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can create element drafts can inject malicious JavaScript that executes in the browser of any higher-privileged user viewing the affected element, allowing account creation and other authenticated actions.

Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can create element drafts can inject malicious JavaScript that executes in the browser of any higher-privileged user viewing the affected element, allowing account creation and other authenticated actions.

EPSS

Процентиль: 9%
0.0019
Низкий

5.1 Medium

CVSS4

6.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.4
nvd
4 дня назад

Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can create element drafts can inject malicious JavaScript that executes in the browser of any higher-privileged user viewing the affected element, allowing account creation and other authenticated actions.

EPSS

Процентиль: 9%
0.0019
Низкий

5.1 Medium

CVSS4

6.4 Medium

CVSS3

Дефекты

CWE-79