CVE-2026-27126: Craft CMS has Stored XSS in Table Field via "HTML" Column Type

Published Feb 23, 2026
·
Updated

A stored Cross-site Scripting (XSS) vulnerability exists in the editableTable.twig component when using the html column type. The application fails to sanitize the input, allowing an attacker to execute arbitrary JavaScript when another user views a page with the malicious table field.

Prerequisites An administrator account allowAdminChanges must be enabled in production, which is against our security recommendations.

Steps to Reproduce 1. Navigate to Settings → Fields and create a new field with Type: Table 1. Add a Column Heading and set Column Type to Single-line text - Note: The vulnerable Column Type is html, but it's not available in the UI dropdown. 1. In Default Values section, add a row with the following payload: html <img src=x onerror="alert('XSS')"> 1. Enable Static Rows 1. Intercept the Save Field request using a proxy tool (e.g., Burp Suite) or use cURL directly 1. Modify the request body and change the types[craft-fields-Table][columns][col3][type] parameter from singleline to html 1. Forward the request to save the field 1. Use the field in any object (e.g. user profile fields) → then visit the any user's profile 1. Notice the XSS execution 1. The XSS will also trigger when an administrator attempts to edit this field, as the malicious payload is executed within the field configuration page, too.

Resources

https://github.com/craftcms/cms/commit/f5d488d9bb6eff7670ed2c2fe30e15692e92c52b

Other sources

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a stored Cross-site Scripting (XSS) vulnerability exists in the editableTable.twig component when using the html column type. The application fails to sanitize the input, allowing an attacker to execute arbitrary JavaScript when another user views a page with the malicious table field. In order to exploit the vulnerability, an attacker must have an administrator account, and allowAdminChanges must be enabled in production, which is against Craft's security recommendations. Versions 4.16.19 and 5.8.23 patch the issue.

MITRE

Affected Software

8 affected componentsFixes available
composer/craftcms/cms>=5.0.0-RC1<=5.8.22
5.8.23
composer/craftcms/cms>=4.5.0-RC1<=4.16.18
4.16.19
CraftCMS Craft CMS>4.5.0<4.16.19
CraftCMS Craft CMS>5.0.0<5.8.23
CraftCMS Craft CMS=4.5.0
CraftCMS Craft CMS=4.5.0-rc1
CraftCMS Craft CMS=5.0.0
CraftCMS Craft CMS=5.0.0-rc1

Event History

Feb 23, 2026
Advisory Published
via GitHub·10:15 PM
Data Sourced
via GitHub·10:15 PM
DescriptionWeaknessAffected Software
Feb 24, 2026
CVE Published
via MITRE·02:30 AM
Data Sourced
via MITRE·02:30 AM
DescriptionWeakness
Data Sourced
via NVD·03:16 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:16 AM
RemedyAffected Software
Jul 15, 58131
Event
via FIRST·07:44 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-27126?

CVE-2026-27126 is classified as a stored Cross-site Scripting (XSS) vulnerability.

2

How do I fix CVE-2026-27126?

To mitigate CVE-2026-27126, upgrade the Craft CMS to version 5.8.23 or 4.16.19 or later.

3

What versions of Craft CMS are affected by CVE-2026-27126?

CVE-2026-27126 affects Craft CMS versions ranging from 5.0.0-RC1 to 5.8.22 and from 4.5.0-RC1 to 4.16.18.

4

What is the impact of exploiting CVE-2026-27126?

Exploitation of CVE-2026-27126 allows an attacker to execute arbitrary JavaScript in the context of another user's session.

5

Is user input related to CVE-2026-27126 properly sanitized?

No, CVE-2026-27126 indicates that user input in the 'editableTable.twig' component is not properly sanitized, leading to XSS vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203