Intel

AIKIDO-2026-10119

craftcms/cms is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)GHSA-4mgv-366x-qxvx Published Feb 5, 2026

35

Low Risk

This Affects:

PHPcraftcms/cms
3.5.0 - 4.16.19
Fixed in 4.17.0
5.0.0 - 5.8.23
Fixed in 5.9.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package contain multiple low-severity cross-site scripting (XSS) issues in control-panel UI output that did not consistently escape untrusted labels and templates. The patch fixes these by escaping label values and other UI text in templates and JavaScript.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

craftcms/cms is vulnerable to Cross-site Scripting (XSS) in versions 3.5.0 - 4.16.19 and 5.0.0 - 5.8.23.

How to fix this

Upgrade the craftcms/cms library to the patch version.