Craft CMS Vulnerable to Stored XSS in Entry Types Name
Description
Published by the National Vulnerability Database
Feb 9, 2026
Published to the GitHub Advisory Database
Feb 9, 2026
Reviewed
Feb 9, 2026
Last updated
Feb 9, 2026
Summary
Stored XSS via Entry Type names. The name is not sanitized when displayed in the Entry Types list.
Proof of Concept
Required Permissions (Attacker)
allowAdminChangesis enabled in production, which is against our security recommendations.Steps to Reproduce
/admin/settings/entry-types).References