{"apiVersion":"1.0","identifier":"CVE-2026-32258","description":"Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. From 1.2.10 through 1.2.12, authenticated backend users with the backend.manage_editor permission can store custom Markup Styles that are compiled by the LESS parser and rendered without sanitization on every backend page, allowing stored cross-site scripting. This issue is fixed in version 1.2.13.","publishedAt":"2026-08-26T17:16:53","lastModifiedAt":"2026-08-26T18:16:27","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-32258","cvssScore":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N","epssProbability":0.00215,"riskScore":0.83,"affectedProduct":"Winter CMS","affectedVersions":">=1.2.10,<1.2.13","vulnerabilityType":"Web app","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-32258","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-32258","en":"https://www.redsauce.net/en/cves/CVE-2026-32258","fr":"https://www.redsauce.net/fr/cves/CVE-2026-32258","pt":"https://www.redsauce.net/pt/cves/CVE-2026-32258","de":"https://www.redsauce.net/de/cves/CVE-2026-32258","sk":"https://www.redsauce.net/sk/cves/CVE-2026-32258","el":"https://www.redsauce.net/el/cves/CVE-2026-32258"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-32258"}}