CVE-2026-25496 | Craft CMS up to 4.16.17/5.8.21 cross site scripting (GHSA-9f5h-mmq6-2x78)
A vulnerability categorized as problematic has been discovered in Craft CMS up to 4.16.17/5.8.21. Affected by this issue is some unknown functionality. Such manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2026-25496. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.