
CVE-2026-25491 Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored XSS via Entry Type names. The name is not sanitized when displayed … https://www.cve.org/CVERecord?id=CVE-2026-25491
Post summary
A stored XSS vulnerability (CVE-2026-25491) exists in Craft CMS (v5.0.0‑RC1 to 5.8.21) due to unsanitized Entry Type names; the post provides technical details but no PoC, exploit, or patch information.
