CVE-2026-55790
HIGHCraft CMS: DOM XSS via GitHub issue title in CraftSupport widget
Title source: cnaDescription
Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22 and 4.0.0-RC1 through 4.17.15, an attacker with only a GitHub account can plant a JavaScript payload in a craftcms/cms issue title. When a Craft admin uses the CraftSupport widget’s "Give feedback" screen and types a search term that returns the poisoned issue, the payload executes in the admin’s control panel session. No control panel account or elevated privileges are required on the attacker’s side. This issue has been fixed in versions 4.17.16 and 5.9.23.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/craftcms/cms/security/advisories/GHSA-24x4-j6x9-rfw5
X_Refsource_Misc x_refsource_misc
https://github.com/craftcms/cms/commit/6bbb66038a268552180ca5c8eed9f46ea25a4417
Scores
CVSS v4
7.4
EPSS
0.0031
EPSS Percentile
23.4%
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (4)
craftcms/cms
4.0.0-RC1 - 4.17.16Packagist
craftcms/cms
5.0.0-RC1 - 5.9.23Packagist
craftcms/cms
>= 4.0.0-RC1, < 4.17.16
craftcms/cms
>= 5.0.0-RC1, < 5.9.23
Published
Jul 01, 2026
Tracked Since
Jul 02, 2026