THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-5cwr-5jxg-pcf6 (medium) — Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles

[GHSA] GHSA-5cwr-5jxg-pcf6 (medium) — Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles

highgithub_advisoriesPublished 2026-08-20

GHSA-5cwr-5jxg-pcf6 Severity: medium CVE: None

Winter: Stored XSS through cached Brand Settings and Editor Settings custom styles

### Impact

Users with the `backend.manage_branding` ("Customize the back-end") or `backend.manage_editor` ("Manage global code editor preferences") permission can provide custom CSS through **Settings → Customize Backend → Styles** or **Settings → Editor Settings → M

Indicators of compromise

Original source: https://github.com/advisories/GHSA-5cwr-5jxg-pcf6