Craftcms

Craft Cms

57 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.19%
  • Published 09.09.2024 17:15:13
  • Last modified 13.09.2024 15:30:45

Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.

  • EPSS 0.34%
  • Published 25.07.2024 17:15:11
  • Last modified 21.11.2024 09:33:05

Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that the attacker ...

  • EPSS 87.25%
  • Published 25.06.2024 21:15:59
  • Last modified 21.11.2024 09:24:22

Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.

  • EPSS 0.37%
  • Published 30.01.2024 09:15:47
  • Last modified 21.11.2024 08:09:28

An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings to Feed-Me Name and Feed-Me URL fields, due to saving a feed using an Asset element type with no volu...

  • EPSS 0.09%
  • Published 30.01.2024 09:15:47
  • Last modified 29.05.2025 15:15:24

Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation.

  • EPSS 0.1%
  • Published 03.01.2024 17:15:12
  • Last modified 21.11.2024 08:54:44

Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. This has been fixed in ...

  • EPSS 93.76%
  • Published 13.09.2023 20:15:08
  • Last modified 21.11.2024 08:21:52

Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has bee...

Exploit
  • EPSS 0.5%
  • Published 23.08.2023 21:15:08
  • Last modified 21.11.2024 08:18:34

Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code execution. This vulnerability can lead to malicious control of vulnerable systems and data exfiltratio...

  • EPSS 0.18%
  • Published 20.06.2023 13:15:09
  • Last modified 09.12.2024 22:15:21

Craft CMS through 4.4.9 is vulnerable to HTML Injection.

Exploit
  • EPSS 3.81%
  • Published 13.06.2023 17:15:14
  • Last modified 03.01.2025 20:15:25

CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution. NOTE: th...