CVE-2026-25488 | Craft CMS up to 4.10.0/5.5.1 Store Management Section Name/Description cross site scripting (GHSA-p6w8-q63m-72c8)
A vulnerability classified as problematic was found in Craft CMS up to 4.10.0/5.5.1. This affects an unknown part of the component Store Management Section. The manipulation of the argument Name/Description results in cross site scripting.
This vulnerability was named CVE-2026-25488. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.