CVE-2026-55790
Received Received - Intake

JavaScript Injection in Craft CMS via GitHub Issue Title

Vulnerability report for CVE-2026-55790, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-01

Last updated on: 2026-07-01

Assigner: GitHub, Inc.

Description

Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22 and 4.0.0-RC1 through 4.17.15, an attacker with only a GitHub account can plant a JavaScript payload in a craftcms/cms issue title. When a Craft admin uses the CraftSupport widget’s "Give feedback" screen and types a search term that returns the poisoned issue, the payload executes in the admin’s control panel session. No control panel account or elevated privileges are required on the attacker’s side. This issue has been fixed in versions 4.17.16 and 5.9.23.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-01
Last Modified
2026-07-01
Generated
2026-07-02
AI Q&A
2026-07-02
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
craftcms cms From 4.0.0-RC1 (inc) to 4.17.15 (inc)
craftcms cms From 5.0.0-RC1 (inc) to 5.9.22 (inc)
craftcms cms 4.17.16
craftcms cms 5.9.23

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Craft CMS versions 5.0.0-RC1 through 5.9.22 and 4.0.0-RC1 through 4.17.15. An attacker who only has a GitHub account can insert a malicious JavaScript payload into the title of an issue in the craftcms/cms GitHub repository.

When a Craft CMS administrator uses the CraftSupport widget's "Give feedback" screen and searches for a term that returns the poisoned issue, the malicious JavaScript payload executes within the admin's control panel session.

Importantly, the attacker does not need any control panel account or elevated privileges within Craft CMS to carry out this attack. The issue has been fixed in versions 4.17.16 and 5.9.23.

Impact Analysis

This vulnerability can lead to the execution of arbitrary JavaScript code in the context of a Craft CMS administrator's control panel session.

Such code execution could allow an attacker to perform actions on behalf of the administrator, potentially leading to unauthorized access, data manipulation, or compromise of the CMS environment.

Since no elevated privileges or control panel accounts are required by the attacker, the risk is significant if an administrator interacts with the compromised feedback search.

Mitigation Strategies

To mitigate this vulnerability, you should upgrade Craft CMS to version 4.17.16 or later, or version 5.9.23 or later, where the issue has been fixed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55790. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart