CVE Explorer
CVE-2026-33051
Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor renders the creator’s fullName as raw HTML due to the use of Template::raw() combined with Craft::t() string interpolation. A low-privileged control panel user (e.g., Author) can set their fullName to an XSS payload via the profile editor, then create an entry with two saves. If an administrator is logged in and executes a specifically crafted payload whi
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"cms","vendor":"craftcms","versions":[{"status":"affected","version":">= 5.9.0-beta.1, < 5.9.11"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:bb21d6898a1881fc6d8bc767d843c52886b5b04328c8285c681ae88a4083895d · sha256:2480781fae852991… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":5.3,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:bb21d6898a1881fc6d8bc767d843c52886b5b04328c8285c681ae88a4083895d · sha256:2480781fae852991… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-79","description":"CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bb21d6898a1881fc6d8bc767d843c52886b5b04328c8285c681ae88a4083895d · sha256:2480781fae852991… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/craftcms/cms/commit/f634a9d21edcafd83a6716047d275f985aba6be1","tags":["x_refsource_MISC"],"url":"https://github.com/craftcms/cms/commit/f634a9d21edcafd83a6716047d275f985aba6be1"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bb21d6898a1881fc6d8bc767d843c52886b5b04328c8285c681ae88a4083895d · sha256:2480781fae852991… · /containers/cna/references/1
{"name":"https://github.com/craftcms/cms/releases/tag/5.9.11","tags":["x_refsource_MISC"],"url":"https://github.com/craftcms/cms/releases/tag/5.9.11"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bb21d6898a1881fc6d8bc767d843c52886b5b04328c8285c681ae88a4083895d · sha256:2480781fae852991… · /containers/cna/references/2
{"name":"https://github.com/craftcms/cms/security/advisories/GHSA-3x4w-mxpf-fhqq","tags":["x_refsource_CONFIRM"],"url":"https://github.com/craftcms/cms/security/advisories/GHSA-3x4w-mxpf-fhqq"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bb21d6898a1881fc6d8bc767d843c52886b5b04328c8285c681ae88a4083895d · sha256:2480781fae852991… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.