{"apiVersion":"1.0","identifier":"CVE-2026-32257","description":"Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Prior to 1.2.13, custom CSS supplied through the Brand Settings Styles field by a backend user with the backend.manage_branding permission is compiled by the LESS parser and rendered without sanitization on every backend page, allowing stored cross-site scripting against backend users. This issue is fixed in version 1.2.13.","publishedAt":"2026-08-26T17:16:53","lastModifiedAt":"2026-08-27T17:17:52","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-32257","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N","epssProbability":0.00215,"riskScore":0.83,"affectedProduct":"Winter CMS","affectedVersions":"<1.2.13","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-32257","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-32257","en":"https://www.redsauce.net/en/cves/CVE-2026-32257","fr":"https://www.redsauce.net/fr/cves/CVE-2026-32257","pt":"https://www.redsauce.net/pt/cves/CVE-2026-32257","de":"https://www.redsauce.net/de/cves/CVE-2026-32257","sk":"https://www.redsauce.net/sk/cves/CVE-2026-32257","el":"https://www.redsauce.net/el/cves/CVE-2026-32257"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-32257"}}