Security Flaw in Winter CMS Allows Unsafe SVG Uploads by Unauthorized Users
CVE-2026-22254
NONE
What is CVE-2026-22254?
Winter CMS, a content management system built on the Laravel PHP framework, has a security issue that affects versions released before 1.2.10. This flaw allows users who have access to the Asset Manager to upload SVG files without the necessary automatic sanitization, potentially leading to exploitation. Attackers would need a backend user account with the 'cms.manage_assets' permission to take advantage of this vulnerability. The developers advise limiting this permission strictly to trusted administrators and developers to mitigate risks. The issue has been resolved in version 1.2.10.
Affected Version(s)
winter < 1.2.10
