CVE-2026-33051

Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor renders the creator’s fullName as raw HTML due to the use of Template::raw() combined with Craft::t() string interpolation. A low-privileged control panel user (e.g., Author) can set their fullName to an XSS payload via the profile editor, then create an entry with two saves. If an administrator is logged in and executes a specifically crafted payload while an elevated session is active, the attacker’s account can be elevated to administrator. This issue has been fixed in version 5.9.11.
Configurations

Configuration 1 (hide)

cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*

History

20 Mar 2026, 19:37

Type Values Removed Values Added
Summary
  • (es) Craft CMS es un sistema de gestión de contenido (CMS). En las versiones 5.9.0-beta.1 a 5.9.10, el menú contextual de revisión/borrador en el editor de elementos renderiza el fullName del creador como HTML sin procesar debido al uso de Template::raw() combinado con la interpolación de cadenas de Craft::t(). Un usuario del panel de control con privilegios bajos (por ejemplo, Autor) puede establecer su fullName a una carga útil de XSS a través del editor de perfil, luego crear una entrada con dos guardados. Si un administrador ha iniciado sesión y ejecuta una carga útil específicamente diseñada mientras una sesión elevada está activa, la cuenta del atacante puede ser elevada a administrador. Este problema ha sido solucionado en la versión 5.9.11.
References () https://github.com/craftcms/cms/commit/f634a9d21edcafd83a6716047d275f985aba6be1 - () https://github.com/craftcms/cms/commit/f634a9d21edcafd83a6716047d275f985aba6be1 - Patch
References () https://github.com/craftcms/cms/releases/tag/5.9.11 - () https://github.com/craftcms/cms/releases/tag/5.9.11 - Product, Release Notes
References () https://github.com/craftcms/cms/security/advisories/GHSA-3x4w-mxpf-fhqq - () https://github.com/craftcms/cms/security/advisories/GHSA-3x4w-mxpf-fhqq - Patch, Vendor Advisory
First Time Craftcms
Craftcms craft Cms
CPE cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

20 Mar 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 06:16

Updated : 2026-03-20 19:37


NVD link : CVE-2026-33051

Mitre link : CVE-2026-33051

CVE.ORG link : CVE-2026-33051


JSON object : View

Products Affected

craftcms

  • craft_cms
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')