Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-v7cf-8gh9-gxmj | Winter: Stored XSS through Brand Settings custom styles |
Thu, 27 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wintercms
Wintercms winter |
|
| Vendors & Products |
Wintercms
Wintercms winter |
Wed, 26 Aug 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compiled by the LESS parser and rendered without sanitization on every backend page, allowing stored cross-site scripting against backend users. This issue is fixed in version 1.2.13. | |
| Title | Winter: Stored XSS through Brand Settings custom styles | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-27T14:33:49.017Z
Reserved: 2026-03-11T15:05:48.396Z
Link: CVE-2026-32257
Updated: 2026-08-27T13:57:01.776Z
Status : Deferred
Published: 2026-08-26T17:16:53.247
Modified: 2026-09-09T21:09:13.080
Link: CVE-2026-32257
No data.
OpenCVE Enrichment
Updated: 2026-08-26T20:30:11Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Github GHSA