
CVE-2026-25496 Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a stored XSS vulnerability exists in t… https://www.cve.org/CVERecord?id=CVE-2026-25496
Post summary
The passage discloses a stored XSS flaw in Craft platform versions 4.0.0‑RC1 to 4.16.17 and 5.0.0‑RC1 to 5.8.21, with no evidence of exploitation or mitigation steps.


