CVE-2026-25489 | Craft CMS up to 4.10.0/5.5.1 Description cross site scripting (GHSA-v585-mf6r-rqrc)
A vulnerability has been found in Craft CMS up to 4.10.0/5.5.1 and classified as problematic. Impacted is an unknown function. Performing a manipulation of the argument Description results in cross site scripting.
This vulnerability is identified as CVE-2026-25489. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.