Loading market data...
← Back to CVE feed

CVE-2026-92590

MEDIUM CVSS 5.4 View on NVD ↗

Description

Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript through editable fields that executes in authenticated Control Panel sessions of higher-privileged users viewing element indexes.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Published: Sep 16, 2026 22:18 UTC Modified: Sep 16, 2026 22:18 UTC