{
  "id": 2360037,
  "title": "GHSA-5CWR-5JXG-PCF6: GHSA-5CWR-5JXG-PCF6: Stored Cross-Site Scripting via Improper Cache Sanitization in Winter CMS Custom Styles",
  "url": "https://urgent.news/2026/08/21/ghsa-5cwr-5jxg-pcf6-ghsa-5cwr-5jxg-pcf6-stored-cross-site-scripting",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-21T10:31:56.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/cverports/ghsa-5cwr-5jxg-pcf6-ghsa-5cwr-5jxg-pcf6-stored-cross-site-scripting-via-improper-cache-5997"
  },
  "original_language": "en",
  "account": "Stored Cross-Site Scripting (XSS) vulnerability in Winter CMS versions prior to 1.2.14 allows attackers with backend branding or editor configuration permissions to inject arbitrary JavaScript. The flaw exists in the custom styles rendering pipeline for Brand Settings and Editor Settings. The attacker's malicious code is written to the cache without sanitization. When subsequent page requests hit the cache, the raw, unsanitized JavaScript is output directly into the backend interface, bypassing security filters and resulting in execution of the attacker's JavaScript in other administrative users' sessions.",
  "summary": "GHSA-5CWR-5JXG-PCF6: Stored Cross-Site Scripting via Improper Cache Sanitization in Winter CMS Custom Styles Vulnerability ID: GHSA-5CWR-5JXG-PCF6 CVSS Score: 8.4 Published: 2026-08-20 Winter CMS versions prior to 1.2.14 are vulnerable to Stored Cross-Site Scripting (XSS) within the administrative backend interface. The flaw resides in the custom styles rendering pipeline for Brand Settings and…",
  "key_points": [
    "Stored XSS vulnerability in Winter CMS versions before 1.2.14",
    "Attackers with backend branding or editor permissions can inject arbitrary JavaScript",
    "Malicious code written to cache without sanitization, executed in other admin sessions"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}