CVE-2024-45406
- EPSS 0.19%
- Veröffentlicht 09.09.2024 17:15:13
- Zuletzt bearbeitet 13.09.2024 15:30:45
Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.
CVE-2024-41800
- EPSS 0.34%
- Veröffentlicht 25.07.2024 17:15:11
- Zuletzt bearbeitet 21.11.2024 09:33:05
Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that the attacker ...
CVE-2024-37843
- EPSS 87.25%
- Veröffentlicht 25.06.2024 21:15:59
- Zuletzt bearbeitet 21.11.2024 09:24:22
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
CVE-2023-36260
- EPSS 0.37%
- Veröffentlicht 30.01.2024 09:15:47
- Zuletzt bearbeitet 21.11.2024 08:09:28
An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings to Feed-Me Name and Feed-Me URL fields, due to saving a feed using an Asset element type with no volu...
CVE-2023-36259
- EPSS 0.09%
- Veröffentlicht 30.01.2024 09:15:47
- Zuletzt bearbeitet 29.05.2025 15:15:24
Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation.
CVE-2024-21622
- EPSS 0.1%
- Veröffentlicht 03.01.2024 17:15:12
- Zuletzt bearbeitet 21.11.2024 08:54:44
Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. This has been fixed in ...
CVE-2023-41892
- EPSS 93.76%
- Veröffentlicht 13.09.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:21:52
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has bee...
CVE-2023-40035
- EPSS 0.5%
- Veröffentlicht 23.08.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 08:18:34
Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code execution. This vulnerability can lead to malicious control of vulnerable systems and data exfiltratio...
CVE-2023-33495
- EPSS 0.18%
- Veröffentlicht 20.06.2023 13:15:09
- Zuletzt bearbeitet 09.12.2024 22:15:21
Craft CMS through 4.4.9 is vulnerable to HTML Injection.
CVE-2023-30179
- EPSS 3.81%
- Veröffentlicht 13.06.2023 17:15:14
- Zuletzt bearbeitet 03.01.2025 20:15:25
CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution. NOTE: th...