craftcms/cms is vulnerable to Cross-Site Scripting (XSS)
54
Medium Risk
The craftcms/cms control panel element table sorter builds expand/collapse toggle buttons for nested structure rows by interpolating the ancestor element title from a data attribute into an HTML string for title and aria-label. Titles that contain quotes or angle brackets can break out of those attributes and inject markup or script when another control panel user views or reorders nested elements. The fix constructs the button with jQuery attribute maps so the title is set safely instead of via string concatenation.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/cms is vulnerable to Cross-Site Scripting (XSS) in versions 4.1.0 - 5.9.22.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant