CVE-2026-79991
- EPSS 0.29%
- Veröffentlicht 02.09.2026 14:25:15
- Zuletzt bearbeitet 03.09.2026 17:45:20
Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the G...
CVE-2026-79990
- EPSS 0.26%
- Veröffentlicht 02.09.2026 14:19:54
- Zuletzt bearbeitet 03.09.2026 17:45:20
Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the G...
CVE-2026-84802
- EPSS 0.17%
- Veröffentlicht 02.09.2026 11:11:16
- Zuletzt bearbeitet 02.09.2026 13:54:48
Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit POST requests to the assets/move-i...
CVE-2026-84801
- EPSS 0.25%
- Veröffentlicht 02.09.2026 11:11:15
- Zuletzt bearbeitet 02.09.2026 16:17:33
Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator accounts. Attackers can generate a val...
CVE-2026-84799
- EPSS 0.17%
- Veröffentlicht 02.09.2026 11:11:14
- Zuletzt bearbeitet 04.09.2026 03:17:45
Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can query these relations to read ...
CVE-2026-84800
- EPSS 0.2%
- Veröffentlicht 02.09.2026 11:11:14
- Zuletzt bearbeitet 02.09.2026 14:17:17
Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, the target asset is resolved by folder and...
CVE-2026-84798
- EPSS 0.2%
- Veröffentlicht 02.09.2026 11:11:13
- Zuletzt bearbeitet 02.09.2026 16:17:33
Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element with checkForProvisionalDraft enabled and runs the deletion authorization check...
CVE-2026-84796
- EPSS 0.26%
- Veröffentlicht 02.09.2026 11:11:12
- Zuletzt bearbeitet 02.09.2026 16:17:33
Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to one site can read, modify, or de...
CVE-2026-84797
- EPSS 0.17%
- Veröffentlicht 02.09.2026 11:11:12
- Zuletzt bearbeitet 02.09.2026 13:54:48
Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows authenticated users with createEntries permission to delete peer provisional drafts. Attackers can exploit the delete...
CVE-2026-84795
- EPSS 0.28%
- Veröffentlicht 02.09.2026 11:11:11
- Zuletzt bearbeitet 02.09.2026 14:17:17
Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when publi...