Craftcms

Craft Cms

98 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 24.03.2026 17:32:27
  • Zuletzt bearbeitet 26.03.2026 20:41:41

Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/entries/move-to-section, even when they do not have...

  • EPSS 0.03%
  • Veröffentlicht 24.03.2026 17:31:28
  • Zuletzt bearbeitet 26.03.2026 17:09:11

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can call assets/image-editor with the ID of a private asset they ...

  • EPSS 0.04%
  • Veröffentlicht 24.03.2026 17:30:20
  • Zuletzt bearbeitet 26.03.2026 14:09:00

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, an unauthenticated user can call assets/generate-transform with a private assetId, receive a valid tr...

  • EPSS 0.08%
  • Veröffentlicht 24.03.2026 17:28:37
  • Zuletzt bearbeitet 26.03.2026 17:08:48

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, guest users can access Config Sync updater index, obtain signed data, and execute state-changing Conf...

  • EPSS 0.01%
  • Veröffentlicht 24.03.2026 17:26:03
  • Zuletzt bearbeitet 26.03.2026 17:08:28

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can read private asset content by calling assets/edit-image with ...

Exploit
  • EPSS 0.06%
  • Veröffentlicht 24.03.2026 17:22:00
  • Zuletzt bearbeitet 26.03.2026 17:08:13

Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.13, a Remote Code Execution (RCE) vulnerability exists in Craft CMS, it can be exploited by any authenticated user with control panel access. This is a bypass of...

  • EPSS 0.03%
  • Veröffentlicht 20.03.2026 05:56:02
  • Zuletzt bearbeitet 20.03.2026 19:37:28

Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor renders the creator’s fullName as raw HTML due to the use of Template::raw() combined with Craft::t() strin...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 16.03.2026 19:04:47
  • Zuletzt bearbeitet 17.03.2026 17:44:31

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their p...

  • EPSS 0.04%
  • Veröffentlicht 16.03.2026 19:02:22
  • Zuletzt bearbeitet 17.03.2026 17:53:45

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, there is a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController. Cra...

  • EPSS 0.04%
  • Veröffentlicht 16.03.2026 18:57:50
  • Zuletzt bearbeitet 17.03.2026 17:55:32

Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTypesController.php, the $settings array from parse_str is passed directly to Craft::configure() without Component::cleanseConfig(). ...