Craft Cms · Craft Cms · CVE-2026-33051
**Name of the Vulnerable Software and Affected Versions**
Craft CMS versions 5.9.0-beta.1 through 5.9.10
**Description**
Craft CMS is a content management system. In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor renders the creator’s `fullName` as raw HTML due to the use of `Template::raw()` combined with `Craft::t()` string interpolation. A low-privileged control panel user (e.g., Author) can set their `fullName` to an XSS payload via the profile editor, then create an entry with two saves. If an administrator is logged in and executes a specifically crafted payload while an elevated session is active, the attacker’s account can be elevated to administrator.
**Recommendations**
Update to Craft CMS version 5.9.11.