THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hq84-x37p-j6q5 (medium) — Winter: Reflected XSS through the search query parameter in the backend Table widget

[GHSA] GHSA-hq84-x37p-j6q5 (medium) — Winter: Reflected XSS through the search query parameter in the backend Table widget

highgithub_advisoriesPublished 2026-08-20

GHSA-hq84-x37p-j6q5 Severity: medium CVE: None

Winter: Reflected XSS through the search query parameter in the backend Table widget

### Impact

Affected versions of Winter CMS render the `search` query parameter without HTML encoding inside a `<script type="text/template">` block in the backend Table widget partial (`modules/backend/widgets/table/partials/_table.php`):

```php value="<?= get('se

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hq84-x37p-j6q5