HIGH
CVE-2026-90561
CVSS
8.7
Description
Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the content manager WYSIWYG preview component that fails to strip script tags from rich text. An Author-role user can store malicious script tags in rich text fields that execute in an Editor or Super Admin's session when the preview pane is expanded, enabling account takeover.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.24%
Probability of exploitation in next 30 days
15th percentile
References
https://github.com/strapi/strapi
https://github.com/strapi/strapi/blob/v5.46.0/packages/core/content-manager/admin/src/pages/EditView/components/FormInputs/Wysiwyg/PreviewWysiwyg.tsx
https://github.com/strapi/strapi/commit/875752612c30f951546904a29469e51e17e0ac37
https://github.com/strapi/strapi/issues/26857
https://www.vulncheck.com/advisories/strapi-4-x-through-4.26.2-and-5-x-before-5.48.1-stored-xss-via-wysiwyg
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.