CVE-2026-55790 Details
Description
Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22 and 4.0.0-RC1 through 4.17.15, an attacker with only a GitHub account can plant a JavaScript payload in a craftcms/cms issue title. When a Craft admin uses the CraftSupport widget’s "Give feedback" screen and types a search term that returns the poisoned issue, the payload executes in the admin’s control panel session. No control panel account or elevated privileges are required on the attacker’s side. This issue has been fixed in versions 4.17.16 and 5.9.23.
A cross-site scripting (XSS) vulnerability has been identified in Craft CMS versions 5.0.0-RC1 prior to 5.9.22 and 4.0.0-RC1 prior to 4.17.15. This issue allows an attacker with a GitHub account to inject a JavaScript payload into the title of a GitHub issue. When a Craft admin searches for the affected issue using the CraftSupport widget's 'Give feedback' feature, the injected payload executes within the admin's control panel session. The vulnerability does not require any special privileges or control panel access for the attacker.
Users can update to Craft CMS versions 4.17.16 or 5.9.23 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 1, 2026CISA-ADP
Assessed Jul 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/craftcms/cms/commit/6bbb66038a268552180ca5c8eed9f46ea25a4417 | [email protected] | Source CodeVendor |
| https://github.com/craftcms/cms/security/advisories/GHSA-24x4-j6x9-rfw5 | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Craft CMS | >= 5.0.0-RC1, < 5.9.22 (semver) >= 4.0.0-RC1, < 4.17.15 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | New CVE Received | [email protected] |
Volerion