Executive brief
A security vulnerability in Craft CMS allows a user with basic 'Author' permissions to take over administrative accounts. By saving a malicious script as an entry title, the attacker can trigger the script to run when an administrator interacts with that entry in the control panel. This can lead to the administrator's email address being changed, allowing the attacker to reset the password and gain full control of the site.
Technical details
A stored XSS vulnerability exists in ElementTableSorter.js due to improper handling of entry titles in the 'Structure' table view. While the server escapes the title into a 'data-title' attribute, the client-side code retrieves this value using jQuery's .data() method (which decodes it) and then concatenates it into a new HTML string for an aria-label without further escaping. An attacker with 'createEntries' and 'saveEntries' permissions can inject a payload into a title. The payload executes when a victim with 'saveEntries' permissions (such as an admin) drags an entry to become a child of the poisoned entry. This can be leveraged for account takeover by performing actions like changing the victim's email address during an elevated session.
Affected products
- Pixel & Tonic Craft CMS >= 5.0.0-RC1, < 5.9.22
Timeline
- 2026-06-16: disclosed: Initial disclosure to vendor
- 2026-07-01: advisory: NVD publication date
- 2026-07-06: advisory: GitHub Advisory published