Stored Cross-Site Scripting Vulnerability in Cockpit CMS
CVE-2026-23695
5.1MEDIUM
What is CVE-2026-23695?
Cockpit CMS versions prior to 2.14.0 are vulnerable to a stored cross-site scripting attack due to improper sanitization of template strings in the Set field type's Display template option. This vulnerability allows attackers with specific permissions to inject arbitrary JavaScript code into the Display template. When users view the collection items list, this malicious script executes in their browsers, potentially compromising sensitive information and user sessions.
Affected Version(s)
Cockpit 0 <= 2.14.0
Cockpit 0 <= 2.14.0
Cockpit 72a83fcfe85ad8330e9ae834bc02fa517b5749e9
