CVE-2026-56382 - Craft CMS - Remote Code Execution via Missing Config Sanitization in FieldsController
CVE ID :CVE-2026-56382 Published : June 21, 2026, 1:26 p.m. | 1 hour, 43 minutes ago Description :Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in the FieldsController::actionRenderCardPreview() method, which passes the...