MEDIUM 5.1 NVD
CVE-2026-92590
Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping
Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript through editable fields that executes in authenticated Control Panel sessions of higher-privileged users viewing element indexes.
References
- https://github.com/craftcms/cms/security/advisories/GHSA-h9jh-v8vc-m5rp
- https://www.vulncheck.com/advisories/craft-cms-5.7.0-before-5.10.13-stored-xss-via-generat
This medium severity vulnerability with a CVSS score of 5.1 was published on 2026-09-16 via NVD.
vulnfeed aggregates 14597 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.