May 19, 2023, 7:53 p.m. | Evan Grant

Tenable Research Advisories www.tenable.com

Stored Cross-Site Scripting in Craft CMS

A researcher at Tenable discovered a post-authentication stored cross-site scripting (XSS) vulnerability in Craft CMS core.


When creating a new field it is possible to inject html, including script tags, and inject an XSS payload which will be executed by users accessing the “Categories” and “Entries” pages.


Proof of Concept:


1. Create a new field with a name such as


2. Create a new category or section and add the field created in step …

authentication cms cross-site html inject payload researcher script scripting tenable vulnerability xss

Social Engineer For Reverse Engineering Exploit Study

@ Independent study | Remote

Data Privacy Manager m/f/d)

@ Coloplast | Hamburg, HH, DE

Cybersecurity Sr. Manager

@ Eastman | Kingsport, TN, US, 37660

KDN IAM Associate Consultant

@ KPMG India | Hyderabad, Telangana, India

Learning Experience Designer in Cybersecurity (f/m/div.) (Salary: ~113.000 EUR p.a.*)

@ Bosch Group | Stuttgart, Germany

Senior Security Engineer - SIEM

@ Samsara | Remote - US