Stored Cross-Site Scripting Vulnerability in Craft CMS by Craft
CVE-2026-84793
4.8MEDIUM
What is CVE-2026-84793?
Craft CMS versions from 5.0.0-RC1 to before 5.10.11 suffer from a stored cross-site scripting vulnerability. This flaw arises because the site name field does not properly sanitize user input. As a result, administrators can input arbitrary JavaScript payloads into this field. These scripts can then execute when other users access certain settings pages within the control panel. This vulnerability poses a significant risk, as it could lead to unauthorized actions or data exposure within the application.
Affected Version(s)
cms 5.0.0-RC1 < 5.10.11
cms 5.10.11
