Security Flaw in Winter CMS Allows Unsafe SVG Uploads by Unauthorized Users
CVE-2026-22254

NONE

Key Information:

Vendor

Wintercms

Status
Vendor
CVE Published:
6 February 2026

What is CVE-2026-22254?

Winter CMS, a content management system built on the Laravel PHP framework, has a security issue that affects versions released before 1.2.10. This flaw allows users who have access to the Asset Manager to upload SVG files without the necessary automatic sanitization, potentially leading to exploitation. Attackers would need a backend user account with the 'cms.manage_assets' permission to take advantage of this vulnerability. The developers advise limiting this permission strictly to trusted administrators and developers to mitigate risks. The issue has been resolved in version 1.2.10.

Affected Version(s)

winter < 1.2.10

References

CVSS V3.1

Score:
Severity:
NONE
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.