THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-2rp4-x2j7-qmcc (medium) — Craft CMS: Stored XSS in the control panel via unescaped draft name

[GHSA] GHSA-2rp4-x2j7-qmcc (medium) — Craft CMS: Stored XSS in the control panel via unescaped draft name

medgithub_advisoriesPublished 2026-08-06

GHSA-2rp4-x2j7-qmcc Severity: medium CVE: None

Craft CMS: Stored XSS in the control panel via unescaped draft name

The control-panel helper that renders element chip/card labels writes an element's `draftName` into the page without HTML-encoding it, while the surrounding path segments are encoded.

A low-privilege control-panel user who can create a draft of an element (for example, an entry) co

MITRE ATT&CK techniques

Original source: https://github.com/advisories/GHSA-2rp4-x2j7-qmcc