A stored cross-site scripting vulnerability, identified as CVE-2026-54503 with a CVSS v3 score of 4.3 , affects RichText fields in plone.app.textfield. This flaw type is categorized under CWE-80 and can be exploited via a crafted RichText field with a specific mimeType and outputMimeType combination, resulting in the execution of arbitrary code in the viewer's browser. The attack vector is network-based (AV:N) and requires low privileges (PR:L). The business impact is significant, as an attacker could potentially inject malicious JavaScript into the application, leading to unauthorized access or data tampering. Affected versions include plone.app.textfield prior to 2.0.2, between 3.0.0 and 3.0.2, and exactly version 4.0.0. The vulnerability can occur when a RichText field is wrongly defined in code with a mimeType and outputMimeType that are the same or when the REST API is used to the same effect, bypassing the safe_html transform and allowing unsanitized values to be emitted via tal:content="structure...".
We recommend you to upgrade plone.app.textfield to version 2.0.2, 3.0.2, or 4.0.1.[/subscribe_to_unlock_form]
A stored cross-site scripting vulnerability, identified as CVE-2026-54503 with a CVSS v3 score of 4.3 , affects RichText fields in plone.app.textfield. This flaw type is categorized under CWE-80 and can be exploited via a crafted RichText field with a specific mimeType and outputMimeType combination, resulting in the execution of arbitrary code in the viewer's browser. The attack vector is network-based (AV:N) and requires low privileges (PR:L). The business impact is significant, as an attacker could potentially inject malicious JavaScript into the application, leading to unauthorized access or data tampering. Affected versions include plone.app.textfield prior to 2.0.2, between 3.0.0 and 3.0.2, and exactly version 4.0.0. The vulnerability can occur when a RichText field is wrongly defined in code with a mimeType and outputMimeType that are the same or when the REST API is used to the same effect, bypassing the safe_html transform and allowing unsanitized values to be emitted via tal:content="structure...".
We recommend you to upgrade plone.app.textfield to version 2.0.2, 3.0.2, or 4.0.1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]