craftcms/cms is vulnerable to Cross-Site Scripting
50
Medium Risk
Affected versions of craftcms/cms are vulnerable to Cross-site Scripting (XSS) via UI labels of elements.
You are affected if you use a vulnerable version of craftcms/cms. The patch of the vulnerability can be reviewed at: https://github.com/craftcms/cms/commit/b7348942f8131b3868ec6f46d615baae50151bb8.
craftcms/cms is vulnerable to Cross-Site Scripting in versions 5.0.0 - 5.1.1.
Upgrade craftcms/cms to the patch version (5.1.2).
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant