
CVE-2026-28784 Craft is a content management system (CMS). Prior to 5.8.22 and 4.16.18, it is possible to craft a malicious payload using the Twig map filter in text fields that acc… https://www.cve.org/CVERecord?id=CVE-2026-28784
Post summary
The tweet announces a vulnerability in Craft CMS versions prior to 5.8.22 and 4.16.18, noting the possibility of crafting malicious payloads using the Twig map filter, but gives no PoC, patch, or exploitation details.
