{"id":"CVE-2026-90561","title":"Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text","summary":"Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store m…","severity":"high","cvss":8.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","cwe":["CWE-79"],"vendor":"strapi","product":"strapi","affected":["strapi >= 4.0.0 <= 4.26.2","strapi >= 5.0.0 < 5.48.1"],"published":"2026-09-13","updated":"2026-09-24","sourceUpdated":"2026-09-24T21:08:22.573","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90561","references":[{"url":"https://github.com/strapi/strapi","label":"disclosure@vulncheck.com"},{"url":"https://github.com/strapi/strapi/blob/v5.46.0/packages/core/content-manager/admin/src/pages/EditView/components/FormInputs/Wysiwyg/PreviewWysiwyg.tsx","label":"disclosure@vulncheck.com"},{"url":"https://github.com/strapi/strapi/commit/875752612c30f951546904a29469e51e17e0ac37","label":"disclosure@vulncheck.com"},{"url":"https://github.com/strapi/strapi/issues/26857","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/strapi-4-x-through-4.26.2-and-5-x-before-5.48.1-stored-xss-via-wysiwyg","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"epss":0.0043,"epssPercentile":0.34513,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-18T17:13:12.927986Z"},"ingestedAt":"2026-09-14T15:23:07.471Z","slug":"CVE-2026-90561","body":"## Overview\n\nStrapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious script tags in rich text fields that execute in an Editor or Super Admin's session when the preview pane is expanded, enabling account takeover.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":47.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}