CVE-2026-31859

medium
Published 2026-03-11 · Modified 2026-05-25
CVSS v3
CVSS v2
VIR risk
5.5

Description

CraftCMS vulnerable to reflective XSS via incomplete return URL sanitization

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.

Package impact

EcosystemPackageVulnerableFixed
php Packagistcraftcms/cms>=4.15.3,<4.17.34.17.3
php Packagistcraftcms/cms>=5.7.5,<5.9.75.9.7
php COMPOSERcraftcms/cms>= 5.7.5, <= 5.9.65.9.7
php COMPOSERcraftcms/cms>= 4.15.3, <= 4.17.24.17.3

References

Verify integrity in audit chain (admin only). AS-IS.