craftcms/cms is vulnerable to Cross-Site Scripting (XSS)
75
High Risk
The craftcms/cms control panel Craft Support widget renders documentation search hits and support-form validation errors into the DOM without escaping user- or server-influenced strings. Search result titles are inserted through jQuery html concatenation, and error messages are appended as raw HTML list items. A control panel user who can influence those values can inject script that runs in another administrator's browser session. The fix HTML-escapes search result text and uses text-node insertion for validation errors.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/cms is vulnerable to Cross-Site Scripting (XSS) in versions 3.5.0 - 4.17.15 and 5.0.0 - 5.9.22.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant