Stored Cross-Site Scripting Vulnerability in Winter CMS by Winter
CVE-2026-32258
8.1HIGH
What is CVE-2026-32258?
Winter CMS, an open-source content management system built on the Laravel PHP framework, contains a vulnerability that allows authenticated backend users, with the 'backend.manage_editor' permission, to create and store custom Markup Styles. The LESS parser compiles these styles without proper sanitization, leading to stored cross-site scripting (XSS) on every backend page. This vulnerability affects versions 1.2.10 through 1.2.12 and has been addressed in version 1.2.13.
Affected Version(s)
winter >= 1.2.10, < 1.2.13
