CVE-2026-23695

MEDIUM

Cockpit CMS 2.14.0 Stored XSS via Set Field Display Template

Title source: cna
STIX 2.1

Description

Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is processed by the $interpolate function using new Function() and rendered via Vue's v-html directive without sanitization. An attacker with content/:models/manage permission can inject arbitrary JavaScript into the Display template, which executes in the browser of any user viewing the collection items list.

Scores

CVSS v3 5.4
EPSS 0.0014
EPSS Percentile 3.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (3)
Cockpit-HQ/Cockpit < 2.14.0
cockpit-hq/cockpit 0 - 2.14.0Packagist
Cockpit-HQ/Cockpit 72a83fcfe85ad8330e9ae834bc02fa517b5749e9
Published May 15, 2026
Tracked Since May 15, 2026