CVE-2026-84793

Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can inject arbitrary JavaScript payloads in the site name that execute when other users view the control panel settings pages.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-02 12:17

Updated : 2026-09-02 14:17


NVD link : CVE-2026-84793

Mitre link : CVE-2026-84793

CVE.ORG link : CVE-2026-84793


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')