Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-vgp4-2fc4-qff2 | Winter: Stored XSS through Editor Settings custom styles |
Wed, 26 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by the LESS parser and rendered without sanitization on every backend page, allowing stored cross-site scripting. This issue is fixed in version 1.2.13. | |
| Title | Winter: Stored XSS through Editor Settings custom styles | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-26T17:35:11.529Z
Reserved: 2026-03-11T15:05:48.396Z
Link: CVE-2026-32258
No data.
Status : Received
Published: 2026-08-26T17:16:53.410
Modified: 2026-08-26T17:16:53.410
Link: CVE-2026-32258
No data.
OpenCVE Enrichment
No data.
Github GHSA