Skip to content

CraftCMS vulnerable to reflective XSS via incomplete return URL sanitization

Moderate severity GitHub Reviewed Published Mar 9, 2026 in craftcms/cms • Updated Mar 11, 2026

No open alerts for this advisory

Give feedback on Dependabot alerts