Craftcms

Craft Cms

146 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.29%
  • Veröffentlicht 02.09.2026 14:25:15
  • Zuletzt bearbeitet 03.09.2026 17:45:20

Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the G...

  • EPSS 0.26%
  • Veröffentlicht 02.09.2026 14:19:54
  • Zuletzt bearbeitet 03.09.2026 17:45:20

Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the G...

  • EPSS 0.17%
  • Veröffentlicht 02.09.2026 11:11:16
  • Zuletzt bearbeitet 02.09.2026 13:54:48

Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit POST requests to the assets/move-i...

  • EPSS 0.25%
  • Veröffentlicht 02.09.2026 11:11:15
  • Zuletzt bearbeitet 02.09.2026 16:17:33

Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator accounts. Attackers can generate a val...

  • EPSS 0.17%
  • Veröffentlicht 02.09.2026 11:11:14
  • Zuletzt bearbeitet 04.09.2026 03:17:45

Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can query these relations to read ...

  • EPSS 0.2%
  • Veröffentlicht 02.09.2026 11:11:14
  • Zuletzt bearbeitet 02.09.2026 14:17:17

Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, the target asset is resolved by folder and...

  • EPSS 0.2%
  • Veröffentlicht 02.09.2026 11:11:13
  • Zuletzt bearbeitet 02.09.2026 16:17:33

Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element with checkForProvisionalDraft enabled and runs the deletion authorization check...

  • EPSS 0.26%
  • Veröffentlicht 02.09.2026 11:11:12
  • Zuletzt bearbeitet 02.09.2026 16:17:33

Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to one site can read, modify, or de...

  • EPSS 0.17%
  • Veröffentlicht 02.09.2026 11:11:12
  • Zuletzt bearbeitet 02.09.2026 13:54:48

Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows authenticated users with createEntries permission to delete peer provisional drafts. Attackers can exploit the delete...

  • EPSS 0.28%
  • Veröffentlicht 02.09.2026 11:11:11
  • Zuletzt bearbeitet 02.09.2026 14:17:17

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges when publi...