CVE-2026-25490 | Craft CMS up to 4.10.0/5.5.1 cross site scripting (GHSA-wq2m-r96q-crrf / EUVD-2026-6103)
A vulnerability, which was classified as problematic, was found in Craft CMS up to 4.10.0/5.5.1. This issue affects some unknown processing. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-25490. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.