Craftcms

Craft Cms

146 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.69%
  • Veröffentlicht 06.10.2026 10:23:25
  • Zuletzt bearbeitet 07.10.2026 04:17:46

Craft CMS 5.10.13.2 contains an authenticated remote code execution vulnerability in the Control Panel action app/render-components. Any authenticated user with basic Control Panel access can submit request-controlled component classes and propert...

  • EPSS 0.26%
  • Veröffentlicht 16.09.2026 21:46:59
  • Zuletzt bearbeitet 22.09.2026 20:25:55

Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are gated only o...

  • EPSS 0.42%
  • Veröffentlicht 16.09.2026 21:46:58
  • Zuletzt bearbeitet 22.09.2026 20:25:55

Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle in Cp::eleme...

  • EPSS 0.24%
  • Veröffentlicht 16.09.2026 21:46:57
  • Zuletzt bearbeitet 22.09.2026 20:25:55

Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever PHP remains av...

  • EPSS 0.14%
  • Veröffentlicht 16.09.2026 21:46:56
  • Zuletzt bearbeitet 22.09.2026 20:25:55

Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript throug...

  • EPSS 0.16%
  • Veröffentlicht 16.09.2026 21:46:55
  • Zuletzt bearbeitet 22.09.2026 20:25:55

Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) opens anothe...

  • EPSS 0.36%
  • Veröffentlicht 10.09.2026 16:17:56
  • Zuletzt bearbeitet 11.09.2026 04:17:55

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

  • EPSS 0.51%
  • Veröffentlicht 08.09.2026 15:14:02
  • Zuletzt bearbeitet 10.09.2026 14:17:09

Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious ...

  • EPSS 0.18%
  • Veröffentlicht 08.09.2026 15:14:01
  • Zuletzt bearbeitet 19.09.2026 15:17:06

Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action). While the action requires the administrateUsers permission, it does not call requireAdmin() when t...

  • EPSS 0.39%
  • Veröffentlicht 08.09.2026 15:14:00
  • Zuletzt bearbeitet 08.09.2026 19:53:13

Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON str...