PT-2026-7138 · Craft · Craft

Mhe4Am

·

Published

2026-02-09

·

Updated

2026-02-09

·

CVE-2026-25491

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Craft versions 5.0.0-RC1 through 5.8.21
Description Craft is susceptible to a stored cross-site scripting (XSS) issue due to insufficient sanitization of Entry Type names. Specifically, the application does not properly sanitize the name when displaying it in the Entry Types list. An attacker with admin access and allowAdminChanges enabled can inject malicious code, such as a JavaScript payload, into the Entry Type name field. This injected code will then be executed when other administrators view the Entry Types list at the /admin/settings/entry-types endpoint. The vulnerability is triggered by providing a crafted input like <img src=x onerror="alert('XSS-EntryTypes')" hidden> as the Entry Type name.
Recommendations Craft versions 5.0.0-RC1 through 5.8.21 should be updated to version 5.8.22 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-25491
GHSA-7PR4-WX9W-MQWR

Affected Products

Craft