Stored Cross-Site Scripting in Strapi Content Manager WYSIWYG Component
CVE-2026-90561

9.3CRITICAL

Key Information:

Vendor

Strapi

Status
Vendor
CVE Published:
13 September 2026

What is CVE-2026-90561?

Strapi versions 4.x up to 4.26.2 and 5.x prior to 5.48.1 are susceptible to a stored cross-site scripting vulnerability in the WYSIWYG preview component of the content manager. This flaw allows users with the Author role to insert malicious script tags into rich text fields. When the preview pane is accessed by an Editor or Super Admin, the scripts execute within their session, potentially leading to an account takeover. Proper validation of input and scripts within this component is essential to prevent such security breaches.

Affected Version(s)

strapi 4.0.0 <= 4.26.2

strapi 5.0.0 < 5.48.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.