CVE-2026-72787 PUBLISHED

Craft CMS 5.0.0-RC1 before 5.10.8 Stored XSS via Draft Name

Assigner: VulnCheck
Reserved: 10.08.2026 Published: 12.08.2026 Updated: 12.08.2026

Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can create element drafts can inject malicious JavaScript that executes in the browser of any higher-privileged user viewing the affected element, allowing account creation and other authenticated actions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor craftcms
Product cms
Versions Default: unaffected
  • affected from 5.0.0-RC1 to 5.10.8 (excl.)
  • Version 5.10.8 is unaffected

Credits

  • je-lv reporter

References

Problem Types

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE