Stored Cross-Site Scripting Vulnerability in Craft CMS by Craft
CVE-2026-84793

4.8MEDIUM

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-84793?

Craft CMS versions from 5.0.0-RC1 to before 5.10.11 suffer from a stored cross-site scripting vulnerability. This flaw arises because the site name field does not properly sanitize user input. As a result, administrators can input arbitrary JavaScript payloads into this field. These scripts can then execute when other users access certain settings pages within the control panel. This vulnerability poses a significant risk, as it could lead to unauthorized actions or data exposure within the application.

Affected Version(s)

cms 5.0.0-RC1 < 5.10.11

cms 5.10.11

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mHe4am
.