Description
Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious script tags in rich text fields that execute in an Editor or Super Admin's session when the preview pane is expanded, enabling account takeover.
Published: 2026-09-13
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting enables account takeover when the WYSIWYG preview pane is expanded
Action: Patch immediately
AI Analysis

Impact

Strapi versions 4.x up to 4.26.2 and 5.x before 5.48.1 contain a stored cross‑site scripting flaw (CWE‑79) in the content manager WYSIWYG preview component. The component fails to strip <script> tags from rich‑text fields, allowing an Author‑role user to embed malicious scripts. When a privileged user, such as an Editor or a Super Admin, opens the preview pane the malicious code executes in that user’s session, effectively granting the attacker control over the account.

Affected Systems

Strapi, the open‑source headless CMS, is affected. The vulnerability exists in all 4.x releases up to 4.26.2 and in all 5.x releases prior to 5.48.1. Only these versions allow authors to store script tags in rich‑text content that will later be rendered in a preview pane.

Risk and Exploitability

The CVSS score of 9.3 marks the flaw as high‑severity. EPSS is < 1% and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to have Author‑role privileges to inject malicious script and then requires a privileged user to open the preview pane for the code to run. The likely attack vector is, and the impact is a full account takeover of privileged accounts, enabling compromise of confidentiality, integrity, and availability of the system.

Generated by OpenCVE AI on September 15, 2026 at 17:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Strapi to 4.26.3 or later, or to 5.48.1 or later.
  • Disable or remove the WYSIWYG preview component or configure it to strip <script> tags server‑side.
  • Restrict the Author role to trusted users, enforce multi‑factor authentication for privileged accounts, and audit rich‑text content for injected scripts.

Generated by OpenCVE AI on September 15, 2026 at 17:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious script tags in rich text fields that execute in an Editor or Super Admin's session when the preview pane is expanded, enabling account takeover.
Title Strapi 4.x through 4.26.2 and 5.x before 5.48.1 Stored XSS via WYSIWYG
First Time appeared Strapi
Strapi strapi
Weaknesses CWE-79
CPEs cpe:2.3:a:strapi:strapi:*:*:*:*:*:*:*:*
Vendors & Products Strapi
Strapi strapi
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:21:46.210Z

Reserved: 2026-09-12T11:13:43.327Z

Link: CVE-2026-90561

cve-icon Vulnrichment

Updated: 2026-09-18T17:17:10.364Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-13T11:17:00.613

Modified: 2026-09-24T21:08:22.573

Link: CVE-2026-90561

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')