Craftcms

Craft Cms

75 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.03%
  • Veröffentlicht 24.02.2026 02:45:45
  • Zuletzt bearbeitet 02.03.2026 20:35:37

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation uses `gethostbyname()`, which only resolves IPv4 addresses. When a hostname has ...

  • EPSS 0.01%
  • Veröffentlicht 24.02.2026 02:42:53
  • Zuletzt bearbeitet 27.02.2026 20:06:52

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a Time-of-Check-Time-of-Use (TOCTOU) race condition exists in Craft CMS’s token validation service for tokens that explicitly set a limite...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 24.02.2026 02:39:44
  • Zuletzt bearbeitet 25.02.2026 19:31:05

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation performs DNS resolution separately from the HTTP request. This Time-of-Check-Tim...

  • EPSS 0.01%
  • Veröffentlicht 24.02.2026 02:30:04
  • Zuletzt bearbeitet 27.02.2026 20:06:03

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a stored Cross-site Scripting (XSS) vulnerability exists in the `editableTable.twig` component when using the `html` column type. The appl...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 09.02.2026 19:55:06
  • Zuletzt bearbeitet 19.02.2026 19:20:46

Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a Remote Code Execution (RCE) vulnerability exists in Craft CMS where the assembleLayoutFromPost() function in src/services/Fiel...

  • EPSS 0.02%
  • Veröffentlicht 09.02.2026 19:50:08
  • Zuletzt bearbeitet 19.02.2026 19:16:05

Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege Escalation vulnerability in Craft CMS’s GraphQL API that allows an authenticated user with write acc...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 09.02.2026 19:45:19
  • Zuletzt bearbeitet 19.02.2026 19:17:02

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a stored XSS vulnerability exists in the Number field type settings. The Prefix and Suffix fields are rendered using the |...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 09.02.2026 19:42:57
  • Zuletzt bearbeitet 19.02.2026 19:18:14

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/get-elements endpoint is vulnerable to SQL Injection via the criteria[orderBy] parameter (JSON body). ...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 09.02.2026 19:41:13
  • Zuletzt bearbeitet 19.02.2026 19:17:44

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation uses filter_var(..., FILTER_VALIDATE_IP) to block a specific list of IP addresses. However...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 09.02.2026 19:36:58
  • Zuletzt bearbeitet 19.02.2026 19:20:06

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation validates the initial URL hostname and resolved IP against a blocklist, but Guzzle follows ...