{"id":"CVE-2026-27126","summary":"Craft CMS has Stored XSS in Table Field via \"HTML\" Column Type","details":"Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a stored Cross-site Scripting (XSS) vulnerability exists in the `editableTable.twig` component when using the `html` column type. The application fails to sanitize the input, allowing an attacker to execute arbitrary JavaScript when another user views a page with the malicious table field. In order to exploit the vulnerability, an attacker must have an administrator account, and `allowAdminChanges` must be enabled in production, which is against Craft's security recommendations. Versions 4.16.19 and 5.8.23 patch the issue.","aliases":["GHSA-3jh3-prx3-w6wc"],"modified":"2026-08-12T03:51:44.409551829Z","published":"2026-02-24T02:30:04.882Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27126.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27126.json"},{"type":"ADVISORY","url":"https://github.com/craftcms/cms/security/advisories/GHSA-3jh3-prx3-w6wc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-27126"},{"type":"FIX","url":"https://github.com/craftcms/cms/commit/f5d488d9bb6eff7670ed2c2fe30e15692e92c52b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/craftcms/cms","events":[{"introduced":"0"},{"fixed":"1a8db788c8b3de85c3aed09ac34046e230079481"},{"fixed":"daf0ed01c7d2c194ba4a405290e43934d020eef2"},{"introduced":"3395410ff69229a3fa3cdd16f677bb08a6f80f0e"},{"fixed":"f5d488d9bb6eff7670ed2c2fe30e15692e92c52b"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING","REFERENCES"],"cpe":["cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*","cpe:2.3:a:craftcms:craft_cms:4.5.0:-:*:*:*:*:*:*","cpe:2.3:a:craftcms:craft_cms:5.0.0:-:*:*:*:*:*:*","cpe:2.3:a:craftcms:craft_cms:5.0.0:rc1:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"4.16.19"},{"fixed":"5.8.23"},{"introduced":"4.5.0-NA"},{"last_affected":"4.5.0-NA"},{"introduced":"5.0.0-NA"},{"last_affected":"5.0.0-NA"},{"introduced":"5.0.0-rc1"},{"last_affected":"5.0.0-rc1"}]}}],"versions":["4.5.0-NA","5.0.0-NA","5.0.0-rc1","4.16.18","5.8.22","4.16.17","5.8.21","4.16.16","5.8.20","4.16.15","5.8.19","4.16.14","5.8.18","4.16.13","5.8.17","4.16.12","5.8.16","4.16.11","5.8.15","5.8.14","4.16.10","4.16.9.1","5.8.13.2","4.16.9","5.8.13.1","5.8.13","5.8.12","4.16.8","5.8.11","4.16.7","5.8.10","4.16.6.1","5.8.9","4.16.6","4.16.5","5.8.8","5.8.7","5.8.6","5.8.5","4.16.4","5.8.4","4.16.3","4.16.0","4.16.2","5.8.3","5.8.2","5.8.1","4.16.1","5.8.0","4.15.7","5.7.11","4.15.6.2","5.7.10","5.7.9","4.15.6.1","5.7.8.2","5.7.8.1","4.15.6","5.7.8","4.15.5","5.7.7","4.15.4","5.7.6","5.7.5","4.15.3","5.7.4","4.15.2","5.7.3","5.7.2","4.15.1","5.7.1.1","4.15.0.2","4.15.0.1","5.7.1","4.15.0","5.7.0","4.14.15","5.6.17","4.14.14","5.6.16","4.14.13","5.6.15","4.14.12","5.6.14","5.6.13","4.14.11.1","4.14.11","5.6.12","4.14.10","5.6.11","5.6.10.2","4.14.9","5.6.10.1","5.6.10","5.6.9.1","4.14.8.1","5.6.9","4.14.8","5.6.8","4.14.7","5.6.7","4.14.6","4.14.5","5.6.6","5.6.5.1","4.14.4","5.6.5","4.14.2","5.6.4","4.14.3","5.6.3","5.6.2","4.14.1","5.6.1","5.6.0.2","4.14.0.2","4.14.0","5.6.0.1","4.14.0.1","5.6.0","4.13.10","4.13.9","4.13.8","4.13.6","4.13.5","4.13.4","4.13.3","4.13.2","4.13.1.1","4.13.1","5.5.0.1","5.5.0","4.13.0","5.4.0","4.12.0","4.11.0.2","5.3.0.3","5.3.0.2","5.3.0.1","4.11.0.1","4.11.0","5.3.0","5.3.0-beta.1","5.3.0-beta.2","4.10.0-beta.2","5.2.0-beta.5","5.2.0-beta.4","5.2.0-beta.3","5.2.0-beta.2","4.10.0-beta.1","5.2.0-beta.1","4.8.11","4.8.10","4.8.9","4.8.8","4.8.7","4.8.6","5.0.0-beta.9","5.0.0-beta.8","5.0.0-beta.7","5.0.0-beta.6","5.0.0-beta.5","5.0.0-beta.4","5.0.0-beta.3","5.0.0-beta.2","5.0.0-beta.1","5.0.0-alpha.13","5.0.0-alpha.12","5.0.0-alpha.11","5.0.0-alpha.10","5.0.0-alpha.9","5.0.0-alpha.7","5.0.0-alpha.8","5.0.0-alpha.5","5.0.0-alpha.6","5.0.0-alpha.4","5.0.0-alpha.3","5.0.0-alpha.2","5.0.0-alpha.1","@craftcms/webpack@0.3.0","@craftcms/webpack@0.2.0","@craftcms/sass@1.0.1","@craftcms/webpack@0.0.1","@craftcms/sass@1.0.0","3.0.0-alpha.2948","3.0.0-alpha.2942","3.0.0-alpha.2939","3.0.0-alpha.2937","3.0.0-alpha.2933","3.0.0-alpha.2928","3.0.0-alpha.2918","3.0.0-alpha.2915","3.0.0-alpha.2687","3.0.0-alpha.2681","3.0.0-alpha.2671","2.3.2617","2.3.2616","2.3.2615","2.3.0-alpha.2612","2.3.0-alpha.2610","2.3.0-alpha.2608","2.3.0-alpha.2606","2.3.0-alpha.2605","2.3.0-alpha.2603","2.3.0-alpha.2602","2.3.0-alpha.2600","2.2.2581","2.2.2579","2.2.0-alpha.2578","2.1.2557","2.1.2556","2.1.2555","2.1.2554","2.1.0-alpha.2552","2.1.0-alpha.2547","2.1.0-alpha.2546","2.0.2539","2.0.2538","2.0.2537","2.0.2536","2.0.2535","2.0.2533","2.0.2532","2.0.2527","2.0.2525","2.0.2524","1.4.0-alpha.2509","1.4.0-alpha.2505","1.4.0-alpha.2503","1.4.0-alpha.2502","1.4.0-alpha.2500","1.4.0-alpha.2499","1.4.0-alpha.2498","1.4.0-alpha.2497","1.4.0-alpha.2493","1.4.0-alpha.2492","1.4.0-alpha.2491","1.4.0-alpha.2490","1.4.0-alpha.2489","1.4.0-alpha.2488","1.2.2339","1.2.2336","1.2.2335","1.2.2333","1.2.0-alpha.2329","1.2.0-alpha.2328","1.2.0-alpha.2322","1.2.0-alpha.2319","1.2.0-alpha.2318","1.2.0-alpha.2312","1.2.0-alpha.2310","1.1.2291","1.1.0-alpha.2288","1.1.0-alpha.2285","1.1.0-alpha.2284","1.1.0-alpha.2283","1.0.2266","1.0.0-alpha.2249","1.0.0-alpha.2248","1.0.0-alpha.2247","0.9.2246","1.0.0-alpha.2245","1.0.0-alpha.2244","0.9.2243","1.0.0-alpha.2242","1.0.0-alpha.2241","1.0.0-alpha.2238","1.0.0-alpha.2237","1.0.0-alpha.2236","0.9.2193","0.9.2189","0.9.2184","0.9.2181","0.9.2177","0.9.2168","0.9.2167","0.9.2157","0.9.2151","0.9.2146","0.9.2124","0.9.2123","0.9.2117","0.9.2116","0.9.2106","0.9.2102","0.9.2103","0.9.2101","0.9.2100","0.9.2094","0.9.2090","0.9.2083","0.9.2081","0.9.2080","0.9.2079","0.9.2078","0.9.2071","0.9.2068","0.9.2065","0.9.2064","0.9.2063"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27126.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}