Craftcms

Craft Cms

124 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.33%
  • Veröffentlicht 12.08.2026 19:07:35
  • Zuletzt bearbeitet 13.08.2026 13:19:17

Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission can reset any user's password i...

  • EPSS 0.19%
  • Veröffentlicht 11.08.2026 12:17:19
  • Zuletzt bearbeitet 11.08.2026 18:18:25

Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can permanently modify that group's category structure...

  • EPSS 0.15%
  • Veröffentlicht 11.08.2026 12:17:18
  • Zuletzt bearbeitet 11.08.2026 16:17:37

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<Volume>Asset mutation, which fetches an attacker-supplied URL server-side. The anti-SSRF validation i...

  • EPSS 0.23%
  • Veröffentlicht 11.08.2026 12:17:17
  • Zuletzt bearbeitet 11.08.2026 18:18:25

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (via ${ENV_VAR} strings in the elementId parameter) into Twig templates before rendering, even when the Twig sandbox is enabled...

  • EPSS 0.54%
  • Veröffentlicht 11.08.2026 12:17:16
  • Zuletzt bearbeitet 11.08.2026 15:17:36

Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechanism. Because Craft marks the ElementInterface as safe (via the AllowedInSandbox attribute) and the sa...

  • EPSS 0.23%
  • Veröffentlicht 11.08.2026 12:17:15
  • Zuletzt bearbeitet 11.08.2026 18:18:25

Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can replay captured login request bodies containing requestOptions and response to create additional aut...

  • EPSS 0.45%
  • Veröffentlicht 11.08.2026 12:17:14
  • Zuletzt bearbeitet 14.08.2026 20:16:56

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. Craft cleanses the outer request-controlled conditio...

  • EPSS 0.22%
  • Veröffentlicht 11.08.2026 12:17:14
  • Zuletzt bearbeitet 11.08.2026 16:17:36

Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create() Twig function restricts class instantiation using a 5-entry blocklist that does not include SplFileObject, allowing an authentica...

  • EPSS 0.21%
  • Veröffentlicht 02.07.2026 16:15:25
  • Zuletzt bearbeitet 02.07.2026 19:16:59

Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above prior to 4.17.14 contain an authorization issue where a forced folder move can delete a conflicting destination folder with...

  • EPSS 0.25%
  • Veröffentlicht 01.07.2026 23:31:31
  • Zuletzt bearbeitet 02.07.2026 15:11:16

Craft CMS is a content management system (CMS). IN versions 5.0.0-RC1 and above prior to 5.9.21, theEntriesController::actionSaveEntry() performs entry-edit permission checks before request-controlled author changes are applied to the model, allowing...