CVE-2026-22254: Winter CMS has Stored Cross-site Scripting (XSS) in Asset Manager
Affected versions of Winter CMS allow users with access to the CMS Asset Manager were able to upload SVGs without automatic sanitization.
To actively exploit this security issue, an attacker would need access to the Backend with a user account with the following permission: cms.manage_assets
The Winter CMS maintainers strongly recommend that the cms.manage_assets permission only be reserved to trusted administrators and developers in general.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-22254 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →