Craftcms

Craft Cms

109 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.33%
  • Veröffentlicht 30.09.2021 00:15:07
  • Zuletzt bearbeitet 21.11.2024 06:26:49

Craft CMS before 3.7.14 allows CSV injection.

  • EPSS 0.99%
  • Veröffentlicht 30.06.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 05:58:44

An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.

  • EPSS 2.82%
  • Veröffentlicht 30.06.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 05:58:44

An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's ses...

  • EPSS 0.73%
  • Veröffentlicht 07.05.2021 19:31:07
  • Zuletzt bearbeitet 21.11.2024 06:07:06

Craft CMS before 3.6.13 has an XSS vulnerability.

Exploit
  • EPSS 0.85%
  • Veröffentlicht 26.03.2021 15:15:12
  • Zuletzt bearbeitet 21.11.2024 05:09:17

Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new.

Exploit
  • EPSS 73.43%
  • Veröffentlicht 04.03.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:41:13

The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.

Exploit
  • EPSS 2.59%
  • Veröffentlicht 31.12.2019 17:15:11
  • Zuletzt bearbeitet 21.11.2024 04:51:50

In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.

  • EPSS 1.61%
  • Veröffentlicht 24.10.2019 16:15:20
  • Zuletzt bearbeitet 21.11.2024 04:29:45

In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.

  • EPSS 0.83%
  • Veröffentlicht 11.10.2019 00:15:10
  • Zuletzt bearbeitet 21.11.2024 04:32:22

Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.

  • EPSS 7.97%
  • Veröffentlicht 26.07.2019 04:15:11
  • Zuletzt bearbeitet 21.11.2024 04:26:21

In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.