← back
CVE-2024-45406

Craft CMS stored XSS in breadcrumb list and title fields

CVSS 5.5 MEDIUMEPSS 0.3%CWE-79CWE-80
Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Affected products
craftcms · cms

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →