CRITICAL
strapi
CVE published 2026-09-13
CVE-2026-90561
CVE-2026-90561 is a critical stored cross-site scripting vulnerability in Strapi instances, allowing malicious script execution in certain user sessions. The vulnerability exists in the content manager WYSIWYG preview component, which fails to strip script tags from rich text. An Author-role user can store malicious script tags that execute in an Editor or Super Admin's session when the preview pane is ex [truncated]