PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-92590 craftcms CVE debrief

CVE-2026-92590 is a stored cross-site scripting vulnerability in Craft CMS versions from 5.7.0 before 5.10.13. The vulnerability is located in the Generated Fields feature, which disables Twig autoescaping and fails to encode cached values. This allows content editors to inject malicious JavaScript through editable fields, which executes in authenticated Control Panel sessions of higher-privileged users viewing element indexes.

Vendor
craftcms
Product
cms
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-16
Original CVE updated
2026-09-19
Advisory published
2026-09-16
Advisory updated
2026-09-19

Who should care

Defenders responsible for Craft CMS installations, especially those with untrusted content editors or high-privileged users, should assess exposure and apply patches or mitigations.

Why it matters

CVE-2026-92590 is a stored cross-site scripting vulnerability in Craft CMS that allows content editors to inject malicious JavaScript, potentially leading to unauthorized actions or data breaches. Defenders should prioritize verifying exposure and applying patches or mitigations.

  • Content editors can inject malicious JavaScript through editable fields
  • Malicious JavaScript executes in authenticated Control Panel sessions of higher-privileged users
  • Potential for unauthorized actions or data breaches
  • Verification of exposure and patch application is necessary

Technical summary

The vulnerability is located in the Generated Fields feature of Craft CMS, which disables Twig autoescaping and fails to encode cached values. This allows content editors to inject malicious JavaScript through editable fields, which executes in authenticated Control Panel sessions of higher-privileged users viewing element indexes. The vulnerability affects Craft CMS versions from 5.7.0 before 5.10.13. Defenders should prioritize verifying exposure and applying patches or mitigations, focusing on systems with untrusted content editors or high-privileged users.

Defensive priority

Defenders should prioritize verifying exposure and applying patches or mitigations, focusing on systems with untrusted content editors or high-privileged users.

Recommended defensive actions

  • Verify exposure by checking Craft CMS versions and configurations
  • Apply patches or updates to version 5.10.13 or later
  • Implement additional security measures for untrusted content editors or high-privileged users
  • Monitor for suspicious activity in Control Panel sessions
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability. Additional information on exploitation or impact is limited. Defenders should verify exposure by checking Craft CMS versions and configurations. The vulnerability allows content editors to inject malicious JavaScript through editable fields, which executes in authenticated Control Panel sessions of higher-privileged users viewing element indexes. Evidence is limited, and defenders should focus on verifying exposure and applying patches or mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-92590 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-92590

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-92590 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-92590

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.