GHSA-m7gw-rffq-rxjm · Severity: low · Ecosystem: composer — Winter CMS has Stored Cross-site Scripting (XSS) in Asset Manager
Winter is a free, open-source content management system (CMS) based on the Laravel PHP framework. Versions of Winter CMS before 1.2.10 allow users with access to the CMS Asset Manager were able to upload SVGs without automatic sanitization. To actively exploit this security issue, an attacker would need access to the Backend with a user account with the following permission: cms.manage_assets. The Winter CMS maintainers strongly recommend that the cms.manage_assets permission only be reserved to trusted administrators and developers in general. This vulnerability is fixed in 1.2.10.
Conclusion & alert: CVE-2026-22254 is rated Low Risk (6.9/100): low exploitation likelihood (EPSS 0.03%). Mandatory action: Low composite risk—no urgent action required; patch on your normal maintenance cycle and revisit priority if CVSS or EPSS increases.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-02-07 | — | 0.03% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 0.0 | 3.1 | NONE |
|
0.9 | 0.0 | [email protected] |
| 3.5 | 3.1 | LOW |
|
0.9 | 2.5 | [email protected] |
GHSA-m7gw-rffq-rxjm · Severity: low · Ecosystem: composer — Winter CMS has Stored Cross-site Scripting (XSS) in Asset Manager
| URL | Tags |
|---|---|
| https://github.com/wintercms/winter/commit/8a7f74b004fcd19721764fc63af0cdb339d9fb65 | Patch |
| https://github.com/wintercms/winter/releases/tag/v1.2.10 | Product Release Notes |
| https://github.com/wintercms/winter/security/advisories/GHSA-m7gw-rffq-rxjm | Patch Vendor Advisory |