Intel

AIKIDO-2026-10211

craftcms/cms is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS)GHSA-fvwq-45qv-xvhv Published Feb 21, 2026

35

Low Risk

This Affects:

PHPcraftcms/cms
3.5.0 - 4.17.2
Fixed in 4.17.3
5.0.0 - 5.9.6
Fixed in 5.9.7
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to cross-site scripting (XSS). The returnUrl value in the setReturnUrl function is not properly validated, allowing URLs with unsafe schemes to be supplied and later used in redirects. This can allow attackers to inject malicious content or execute script code in the user’s browser.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

craftcms/cms is vulnerable to Cross-site Scripting (XSS) in versions 3.5.0 - 4.17.2 and 5.0.0 - 5.9.6.

How to fix this

Upgrade the craftcms/cms library to the patch version.