
CVE-2026-28781 Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the authorId attribute. … https://www.cve.org/CVERecord?id=CVE-2026-28781
Post summary
The snippet references CVE-2026-28781 and describes a mass assignment flaw in Craft CMS before certain versions, but no exploit, patch, or PoC details are provided.
