CVE-2026-105985
- EPSS 0.69%
- Veröffentlicht 06.10.2026 10:23:25
- Zuletzt bearbeitet 07.10.2026 04:17:46
Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components. Any authenticated user with basic Control Panel access can submit request-controlled component classes and propert...
CVE-2026-92594
- EPSS 0.26%
- Veröffentlicht 16.09.2026 21:46:59
- Zuletzt bearbeitet 22.09.2026 20:25:55
Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are gated only o...
CVE-2026-92593
- EPSS 0.42%
- Veröffentlicht 16.09.2026 21:46:58
- Zuletzt bearbeitet 22.09.2026 20:25:55
Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle in Cp::eleme...
CVE-2026-92591
- EPSS 0.24%
- Veröffentlicht 16.09.2026 21:46:57
- Zuletzt bearbeitet 22.09.2026 20:25:55
Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever PHP remains av...
CVE-2026-92590
- EPSS 0.14%
- Veröffentlicht 16.09.2026 21:46:56
- Zuletzt bearbeitet 22.09.2026 20:25:55
Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript throug...
CVE-2026-92589
- EPSS 0.16%
- Veröffentlicht 16.09.2026 21:46:55
- Zuletzt bearbeitet 22.09.2026 20:25:55
Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) opens anothe...
CVE-2026-79987
- EPSS 0.36%
- Veröffentlicht 10.09.2026 16:17:56
- Zuletzt bearbeitet 11.09.2026 04:17:55
A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.
CVE-2026-86732
- EPSS 0.51%
- Veröffentlicht 08.09.2026 15:14:02
- Zuletzt bearbeitet 10.09.2026 14:17:09
Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious ...
CVE-2026-86731
- EPSS 0.18%
- Veröffentlicht 08.09.2026 15:14:01
- Zuletzt bearbeitet 19.09.2026 15:17:06
Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action). While the action requires the administrateUsers permission, it does not call requireAdmin() when t...
CVE-2026-86730
- EPSS 0.39%
- Veröffentlicht 08.09.2026 15:14:00
- Zuletzt bearbeitet 08.09.2026 19:53:13
Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON str...