CVE-2026-55794
- EPSS 0.29%
- Veröffentlicht 01.07.2026 23:26:22
- Zuletzt bearbeitet 02.07.2026 15:12:53
Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control panel users with the ability to edit entries can execute unsandboxed Twig code via the HTTP Referrer header, potentially leading to authenticated RCE...
- EPSS 0.27%
- Veröffentlicht 01.07.2026 23:20:28
- Zuletzt bearbeitet 02.07.2026 15:17:06
Craft CMS is a content management system (CMS). In versions starting from 4.0.0-RC1 and prior to 4.18.0, and 5.0.0-RC1 and above, prior to 5.10.0, the dataUrl() Twig function is included in Craft’s Twig sandbox allowlist, allowing any control panel u...
CVE-2026-50284
- EPSS 0.25%
- Veröffentlicht 01.07.2026 22:37:30
- Zuletzt bearbeitet 02.07.2026 15:11:16
Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.21 and 4.0.0-RC1 through 4.17.14, theAssetsController::actionDeleteFolder() only requires the deleteAssets:<volume-uid> permission for the target folder. It never enfor...
CVE-2026-50283
- EPSS 0.27%
- Veröffentlicht 01.07.2026 22:20:01
- Zuletzt bearbeitet 02.07.2026 15:17:02
Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 through 4.17.13 contain an authorization issue in the AssetsController::actionReplaceFile that can delete a source asset without source delete permission...
CVE-2026-55793
- EPSS 0.26%
- Veröffentlicht 01.07.2026 21:57:58
- Zuletzt bearbeitet 02.07.2026 16:16:33
Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22, an author-level control panel user can store a malicious JavaScript payload in an entry title. When an admin, or any control panel user with saveEntries for the sam...
CVE-2026-56394
- EPSS 0.34%
- Veröffentlicht 21.06.2026 13:27:02
- Zuletzt bearbeitet 23.06.2026 14:17:24
Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing traversal se...
CVE-2026-56383
- EPSS 0.31%
- Veröffentlicht 21.06.2026 13:26:59
- Zuletzt bearbeitet 23.06.2026 15:16:39
Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the 'Row Heading' column type. The application fails to sanitize input within row heading default values, allowing an attacker with an...
CVE-2026-56381
- EPSS 0.25%
- Veröffentlicht 21.06.2026 13:26:58
- Zuletzt bearbeitet 23.06.2026 04:17:43
Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where user group names are rendered without proper HTML escaping. Attackers with admin access can inject arbitrary JavaScript via the u...
CVE-2026-56382
- EPSS 0.49%
- Veröffentlicht 21.06.2026 13:26:58
- Zuletzt bearbeitet 22.06.2026 18:40:05
Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in the FieldsController::actionRenderCardPreview() method, which passes the fieldLayoutConfig POST parameter directly to Fields::c...
CVE-2026-31266
- EPSS 0.28%
- Veröffentlicht 27.05.2026 15:16:26
- Zuletzt bearbeitet 27.05.2026 20:00:46
Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).