CVE-2025-57811
- EPSS 0.39%
- Veröffentlicht 25.08.2025 17:52:07
- Zuletzt bearbeitet 03.09.2025 17:43:47
Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig SSTI (Server-Side Template Injection). This is a follow-up to CVE-2024-5...
CVE-2025-54417
- EPSS 0.06%
- Veröffentlicht 09.08.2025 01:31:23
- Zuletzt bearbeitet 02.09.2025 19:23:07
Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass CVE-2025-23209: "Craft CMS has a potential RCE with a compromised security key". To exploit this vuln...
CVE-2025-35939
- EPSS 33.05%
- Veröffentlicht 07.05.2025 22:41:29
- Zuletzt bearbeitet 03.06.2025 20:59:34
Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login pag...
CVE-2025-46731
- EPSS 0.09%
- Veröffentlicht 05.05.2025 19:35:31
- Zuletzt bearbeitet 03.09.2025 18:06:16
Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW...
- EPSS 76.28%
- Veröffentlicht 25.04.2025 15:04:06
- Zuletzt bearbeitet 28.04.2025 20:57:06
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code ex...
CVE-2025-23209
- EPSS 3.62%
- Veröffentlicht 18.01.2025 01:15:07
- Zuletzt bearbeitet 21.02.2025 14:48:55
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyon...
CVE-2024-56145
- EPSS 93.75%
- Veröffentlicht 18.12.2024 21:15:08
- Zuletzt bearbeitet 03.06.2025 20:48:48
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an un...
CVE-2024-52292
- EPSS 0.2%
- Veröffentlicht 13.11.2024 17:15:12
- Zuletzt bearbeitet 19.11.2024 18:27:21
Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, reads the file's content, and converts it into a Bas...
CVE-2024-52291
- EPSS 0.22%
- Veröffentlicht 13.11.2024 17:15:12
- Zuletzt bearbeitet 19.11.2024 18:06:42
Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a double file:// scheme (e.g., file://file:////). This enables the attacker to specify sensitive folders as...
CVE-2024-52293
- EPSS 4.52%
- Veröffentlicht 13.11.2024 16:15:19
- Zuletzt bearbeitet 19.11.2024 17:51:39
Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could lead to Remote Code Execution on the server via twig SSTI. This is a sequel to CVE-2023-40035. This v...