CVE-2026-90561 | Strapi up to 4.26.2/5.48.0 Content Manager WYSIWYG Preview cross site scripting
A vulnerability categorized as problematic has been discovered in Strapi up to 4.26.2/5.48.0. The impacted element is an unknown function of the component Content Manager WYSIWYG Preview Component. The manipulation results in cross site scripting.
This vulnerability was named CVE-2026-90561. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More