Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 12 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can create element drafts can inject malicious JavaScript that executes in the browser of any higher-privileged user viewing the affected element, allowing account creation and other authenticated actions. | |
| Title | Craft CMS 5.0.0-RC1 before 5.10.8 Stored XSS via Draft Name | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-12T20:55:22.458Z
Reserved: 2026-08-10T15:10:15.963Z
Link: CVE-2026-72787
Updated: 2026-08-12T20:46:49.063Z
Status : Received
Published: 2026-08-12T20:17:49.977
Modified: 2026-08-12T21:17:39.830
Link: CVE-2026-72787
No data.
OpenCVE Enrichment
No data.