


Perceptive Security
SOC/SIEM Consultancy

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with t…
Published:
26 augustus 2026 om 00:00:00
Alert date:
26 augustus 2026 om 20:02:55
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
CVE-2026-32258 affects Winter CMS versions 1.2.10 through 1.2.12, a free open-source CMS built on the Laravel PHP framework. Authenticated backend users with the backend.manage_editor permission can exploit this vulnerability by storing malicious custom Markup Styles. These styles are compiled by the LESS parser and rendered without sanitization on every backend page, resulting in stored cross-site scripting (XSS). The vulnerability requires authentication and a specific permission, somewhat limiting the attack surface, but stored XSS can have significant impact affecting all users viewing the backend. The issue has been patched in version 1.2.13. A fix commit and security advisory are available on the Winter CMS GitHub repository.
Technical details
Mitigation steps:
Affected products:
Winter CMS 1.2.10
Winter CMS 1.2.11
Winter CMS 1.2.12
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-32258
https://github.com/wintercms/winter/commit/d28f0b9474af79cfaa80eeb9d691f7a7c4469720
https://github.com/wintercms/winter/security/advisories/GHSA-vgp4-2fc4-qff2
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
