Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
26 changes: 26 additions & 0 deletions gems/alchemy_cms/GHSA-4qhx-6wrv-5hg2.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
---
gem: alchemy_cms
ghsa: 4qhx-6wrv-5hg2
url: https://github.com/AlchemyCMS/alchemy_cms/security/advisories/GHSA-4qhx-6wrv-5hg2
title: Account Takeover & Privilege-Escalation To Admin via Stored
XSS in Menu Node Name Rendered in Admin Configure Dialog Page Content
date: 2026-09-02
description: |
An improper input sanitization vulnerability in the menu node name
rendering allows Author-level users to inject stored JavaScript
that executes in an Admin's browser when they open the configure
dialog for a page referencing the malicious node. The payload
executes with the Admin's session privileges, allowing an attacker
to perform administrative actions and create an attacker-controlled
administrator account, resulting in full account takeover and
privilege escalation.
cvss_v3: 9.0
patched_versions:
- ">= 8.3.8"
related:
url:
- https://github.com/AlchemyCMS/alchemy_cms/releases/tag/v8.3.8
- https://github.com/AlchemyCMS/alchemy_cms/security/advisories/GHSA-4qhx-6wrv-5hg2
notes: |
- No CVE in GHSA url.
- cvss_v3 from GHSA url.
26 changes: 26 additions & 0 deletions gems/alchemy_cms/GHSA-g7vv-4mjj-6fgm.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,26 @@
---
gem: alchemy_cms
ghsa: g7vv-4mjj-6fgm
url: https://github.com/AlchemyCMS/alchemy_cms/security/advisories/GHSA-g7vv-4mjj-6fgm
title: Account Takeover & Privilege-Escalation To Admin via Stored
XSS in Menu Node Name Rendered in Page Properties Configure Dialog
date: 2026-09-02
description: |
An improper input sanitization vulnerability in the Page Properties
menu node rendering allows Author-level users to inject stored
JavaScript that executes in an Admin's browser when they open the
Configure dialog for a page containing the malicious node. The
payload executes with the Admin's session privileges, allowing
an attacker to perform administrative actions and create an
attacker-controlled administrator account, resulting in full
account takeover and privilege escalation.
cvss_v3: 9.0
patched_versions:
- ">= 8.3.8"
related:
url:
- https://github.com/AlchemyCMS/alchemy_cms/releases/tag/v8.3.8
- https://github.com/AlchemyCMS/alchemy_cms/security/advisories/GHSA-g7vv-4mjj-6fgm
notes: |
- No CVE in GHSA url.
- cvss_v3 from GHSA url.