Medium severity5.4NVD Advisory· Published May 26, 2023· Updated Jun 17, 2026
CVE-2023-2817
CVE-2023-2817
Description
A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
craftcms/cmsPackagist | >= 4.0.0-RC1, < 4.4.12 | 4.4.12 |
Affected products
3Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.