Vulnerability CVE-2024-45406


Published: 2024-09-09

Description:
Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://github.com/craftcms/cms/security/advisories/GHSA-28h4-788g-rh42
https://github.com/craftcms/cms/commit/b7348942f8131b3868ec6f46d615baae50151bb8

Copyright 2026, cxsecurity.com

 

Back to Top