top of page
perceptive_background_267k.jpg

Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with t…

Published:

26 augustus 2026 om 00:00:00

Alert date:

26 augustus 2026 om 20:02:55

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

CVE-2026-32258 affects Winter CMS versions 1.2.10 through 1.2.12, a free open-source CMS built on the Laravel PHP framework. Authenticated backend users with the backend.manage_editor permission can exploit this vulnerability by storing malicious custom Markup Styles. These styles are compiled by the LESS parser and rendered without sanitization on every backend page, resulting in stored cross-site scripting (XSS). The vulnerability requires authentication and a specific permission, somewhat limiting the attack surface, but stored XSS can have significant impact affecting all users viewing the backend. The issue has been patched in version 1.2.13. A fix commit and security advisory are available on the Winter CMS GitHub repository.

Technical details

Mitigation steps:

Affected products:

Winter CMS 1.2.10
Winter CMS 1.2.11
Winter CMS 1.2.12

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page