Junglewise Threat Intelligence

Craft CMS stored XSS in Table field Row Heading

Severity: medium · CVSS 4.8 · Published 2026-06-21

Technologies: craftcms/cms (Packagist). Vendors: Craft CMS, Packagist.

Executive brief

Craft CMS, a platform used for building and managing websites, contains a security flaw in how it handles table data. An authorized administrator could save malicious code into a table's row headings, which would then execute in the browser of any other user viewing that table. This could lead to unauthorized actions being performed on behalf of other users or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the `editableTable.twig` component of Craft CMS. The root cause is a failure to sanitize input within the 'Row Heading' column type default values. An attacker with administrative privileges (specifically with `allowAdminChanges` enabled) can inject arbitrary JavaScript into the row heading. This script executes in the context of any user who subsequently views a page containing the affected table field. The vulnerability is fixed in versions 4.16.19 and 5.8.23 by implementing proper HTML encoding in the `_getInputHtml()` method of the Table field class.

Affected products

  • Craft CMS CMS >= 4.5.0-beta.1, <= 4.16.18; >= 5.0.0-RC1, <= 5.8.22

Timeline

  • 2026-02-23: advisory: Original advisory GHSA-6j87-m5qx-9fqp published
  • 2026-06-21: disclosed: CVE-2026-56383 published
  • 2026-08-06: other: Duplicate advisory GHSA-5w9j-w5p8-r4p7 withdrawn

References

Related threats