Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript through editable
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92592 | 8.8 HIGH | Craft CMS before 4.18.6 Remote Code Execution via signed cookie |
| CVE-2026-92593 | 8.8 HIGH | Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution |
| CVE-2026-92594 | 7.5 HIGH | Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL |
| CVE-2026-92591 | 5.9 MEDIUM | Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer |
| CVE-2026-92589 | 4.3 MEDIUM | Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder |
No comments yet