Stored Cross-Site Scripting Vulnerability in Craft CMS by Craft
CVE-2026-72787
5.1MEDIUM
What is CVE-2026-72787?
Craft CMS versions prior to 5.10.8 are susceptible to a stored cross-site scripting (XSS) vulnerability within the control panel. Draft names are rendered without proper HTML encoding in element chips and cards, allowing low-privilege users to inject malicious JavaScript. When higher-privileged users access these elements, the injected scripts execute in their browsers, posing significant risks such as unauthorized account creation and execution of other authenticated actions.
Affected Version(s)
cms 5.0.0-RC1 < 5.10.8
cms 5.10.8
