Impact
This vulnerability allows a low‑privilege user who can create element drafts in Craft CMS to inject arbitrary JavaScript into the draft name. The injected code is rendered unescaped in the control panel’s element chips and cards, causing it to run in the browsers of any higher‑privileged user who accesses the same element. An attacker can hijack sessions, create new accounts, and perform authenticated actions without direct admin access.
Affected Systems
The flaw exists in all Craft CMS releases prior to version 5.10.8, including the 5.0.0‑RC1 release. The affected product is Craft CMS under the vendor craftcms. The vulnerability is tied specifically to the control panel component that displays draft names.
Risk and Exploitability
The CVSS base score of 5.1 indicates a moderate severity. Because the attack requires authentication with at least draft‑creation rights, an attacker needs a low‑privileged account but can target privileged users. EPSS is not available, and the vulnerability is not listed in the CISA KEV, suggesting no widespread public exploit has been reported yet. However, the stored XSS payload can be used to perform account takeover or privileged actions, so the risk to organizations that maintain low‑privileged accounts remains significant.
OpenCVE Enrichment