CVE-2026-92590: Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields

Published Sep 16, 2026
·
Updated

Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript through editable fields that executes in authenticated Control Panel sessions of higher-privileged users viewing element indexes.

Affected Software

1 affected component
Craft CMS Craft CMS>=5.7.0<5.10.13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Craft CMS to a version that resolves this vulnerability.

    Fixed in 5.10.13

Event History

Sep 16, 2026
CVE Published
via MITRE·09:46 PM
Data Sourced
via MITRE·09:46 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue, and who is at risk from the injected code?

A content editor who can modify editable fields can inject the malicious JavaScript. The code executes when a higher-privileged authenticated user views affected element indexes in the Control Panel.

2

Are all Craft CMS deployments affected?

The issue affects Craft CMS versions from 5.7.0 up to, but not including, 5.10.13, where the Generated Fields feature is in use. The described attack relies on editable fields and Control Panel users viewing element indexes.

3

What access and interaction are required for exploitation?

The attacker needs authenticated content-editor access and the ability to place payloads in editable fields. A higher-privileged authenticated user must subsequently view an affected element index for the stored script to execute.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203