CVE-2026-25491

Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored XSS via Entry Type names. The name is not sanitized when displayed in the Entry Types list. This vulnerability is fixed in 5.8.22.
Configurations

Configuration 1 (hide)

cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*

History

19 Feb 2026, 19:26

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
CPE cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Summary
  • (es) Craft es una plataforma para crear experiencias digitales. Desde la 5.0.0-RC1 hasta la 5.8.21, Craft tiene un XSS almacenado a través de los nombres de los tipos de entrada. El nombre no se sanea cuando se muestra en la lista de tipos de entrada. Esta vulnerabilidad está corregida en la 5.8.22.
First Time Craftcms
Craftcms craft Cms
References () https://github.com/craftcms/cms/commit/cfd6ba0e2ce1a59a02d75cae6558c4ace1ab8bd4 - () https://github.com/craftcms/cms/commit/cfd6ba0e2ce1a59a02d75cae6558c4ace1ab8bd4 - Patch
References () https://github.com/craftcms/cms/releases/tag/5.8.22 - () https://github.com/craftcms/cms/releases/tag/5.8.22 - Product, Release Notes
References () https://github.com/craftcms/cms/security/advisories/GHSA-7pr4-wx9w-mqwr - () https://github.com/craftcms/cms/security/advisories/GHSA-7pr4-wx9w-mqwr - Exploit, Patch, Vendor Advisory

09 Feb 2026, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-09 20:15

Updated : 2026-02-19 19:26


NVD link : CVE-2026-25491

Mitre link : CVE-2026-25491

CVE.ORG link : CVE-2026-25491


JSON object : View

Products Affected

craftcms

  • craft_cms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')