
A stored cross-site scripting (XSS) vulnerability exists in Decap CMS up to version 3.8.3. The issue affects multiple input fields in the **admin interface** and is triggered when a privileged user opens the **content preview panel** of a malicious entry.
A stored cross-site scripting (XSS) vulnerability exists in Decap CMS up to version 3.8.3.
The issue affects multiple input fields in the admin interface and is triggered when a privileged user opens the content preview panel of a malicious entry.
">
Login as Contributor/Editor (low privilege).
Create a new blog entry.
Insert the payload into one of the vulnerable fields (e.g., title).
Save the entry.
Login as Admin (high privilege).
Open the entry in Preview.
Payload executes in the admin’s browser context.
Vulnerable fields

Admin opens preview → payload executes:
