Description
Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript through editable fields that executes in authenticated Control Panel sessions of higher-privileged users viewing element indexes.
Published: 2026-09-16
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting in the Generated Fields feature
Action: Apply Patch
AI Analysis

Impact

The flaw allows a content editor to store malicious JavaScript in editable fields that are rendered by the Control Panel’s element indexes. Because the Generated Fields feature disables Twig auto‑escaping and does not encode cached values, the attacker’s code is executed in the browsers of authenticated, higher‑privileged users. This stored XSS (CWE‑79) can disclose session information, deface content, or enable further attacks within the application. The exploit requires only that an editor create or edit a field containing script payloads; no additional network access or external injection is needed.

Affected Systems

The defect exists in Craft CMS from version 5.7.0 up to, but not including, 5.10.13. Users running any of these vulnerable versions, especially those with editing or administrative privileges in the Control Panel, are impacted.

Risk and Exploitability

The CVSS score of 5.1 denotes a medium severity vulnerability, and the EPSS score is below 1 %, indicating a low probability of automated exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Attackers can typically exploit the flaw by logging as a content editor, entering a crafted payload into a generated field, and then having a higher‑privileged Control Panel user view the element index. The code runs in the browser of the viewing user, allowing for cookie theft, UI manipulation, or masquerading as legitimate application scripts. No advanced prerequisites beyond valid credentials are required.

Generated by OpenCVE AI on September 18, 2026 at 05:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Craft CMS to version 5.10.13 or later
  • Restrict editing permissions for content editors and limit the use of Generated Fields to trusted users
  • Deploy a strict Content Security Policy to disable inline scripts and mitigate XSS

Generated by OpenCVE AI on September 18, 2026 at 05:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript through editable fields that executes in authenticated Control Panel sessions of higher-privileged users viewing element indexes.
Title Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields
First Time appeared Craftcms
Craftcms craft Cms
Weaknesses CWE-79
CPEs cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Vendors & Products Craftcms
Craftcms craft Cms
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Craftcms Craft Cms
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T02:04:23.960Z

Reserved: 2026-09-16T13:47:49.170Z

Link: CVE-2026-92590

cve-icon Vulnrichment

Updated: 2026-09-19T02:04:19.855Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T22:18:29.730

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-92590

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')