CVE-2026-25483 | Craft CMS up to 4.10.0/5.5.1 History Message cross site scripting (GHSA-8478-rmjg-mjj5)
A vulnerability categorized as problematic has been discovered in Craft CMS up to 4.10.0/5.5.1. The impacted element is an unknown function of the component History Message Handler. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-25483. The attack can be launched remotely. No exploit exists.
It is advisable to upgrade the affected component.