{"id":"CVE-2026-92590","title":"Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values","summary":"Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious Java…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-79"],"vendor":"craftcms","product":"cms","affected":["cms >= 5.7.0 < 5.10.13"],"published":"2026-09-16","updated":"2026-09-19","sourceUpdated":"2026-09-19T03:17:17.460","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-92590","references":[{"url":"https://github.com/craftcms/cms/security/advisories/GHSA-h9jh-v8vc-m5rp","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/craft-cms-5.7.0-before-5.10.13-stored-xss-via-generated-fields","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"epss":0.00138,"epssPercentile":0.03556,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-19T02:04:13.074478Z"},"ingestedAt":"2026-09-16T22:06:50.929Z","slug":"CVE-2026-92590","body":"## Overview\n\nCraft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript through editable fields that executes in authenticated Control Panel sessions of higher-privileged users viewing element indexes.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}