Vulnerabilities/

Sveltia CMS: Stored XSS in entry summary rendering via entity-decoded HTML

Severity:
Low

Description

A stored cross-site scripting (XSS) vulnerability affected entry summary rendering in Sveltia CMS.

Entry summaries that allowed limited Markdown were parsed, sanitized, and then HTML entities were decoded.

Recommendation

Update the @sveltia/cms package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@sveltia/cms
Anything's wrong? Let us know Last updated on May 18, 2026