A vulnerability identified as problematic has been detected in CraftCMS CMS up to 5.10.7 . Affected by this issue is some unknown functionality of the component Control Panel . Performing a manipulation results in cross site scripting. This vulnerability is identified as CVE-2026-72787 . The attack can be initiated remotely. There is not any exploit available. You should upgrade the affected component.