
CVE-2026-28696 Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal reference tags (e.g.… https://www.cve.org/CVERecord?id=CVE-2026-28696
Post summary
A vulnerability in Craft CMS’s GraphQL @parseRefs directive is disclosed, with patched versions noted, but no exploit or active exploitation is reported.

