CVE-2026-72787: Craft CMS 5.0.0-RC1 before 5.10.8 Stored XSS via Draft Name
Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can create element drafts can inject malicious JavaScript that executes in the browser of any higher-privileged user viewing the affected element, allowing account creation and other authenticated actions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
craft-cmsto a version that resolves this vulnerability.Fixed in 5.10.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch Craft CMS 5.0.0-RC1 before 5.10.8 Stored XSS via Draft Name
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72787?
The severity of CVE-2026-72787 is medium with a score of 6.4.
What vulnerability does CVE-2026-72787 refer to?
CVE-2026-72787 refers to a stored cross-site scripting vulnerability in Craft CMS versions before 5.10.8.
How do I fix CVE-2026-72787?
To fix CVE-2026-72787, upgrade Craft CMS to version 5.10.8 or later.
What impact does CVE-2026-72787 have on users?
CVE-2026-72787 could allow a low-privilege user to inject malicious JavaScript that executes in the browser.
Which versions of Craft CMS are affected by CVE-2026-72787?
Craft CMS versions prior to 5.10.8 are affected by CVE-2026-72787.