Craftcms

Craft Cms

75 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.01%
  • Veröffentlicht 09.02.2026 19:33:24
  • Zuletzt bearbeitet 19.02.2026 19:12:55

Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save_images_Asset GraphQL mutation can be abused to fetch internal URLs by providing a domain name that resolves to an internal IP add...

Exploit
  • EPSS 0.01%
  • Veröffentlicht 09.02.2026 19:25:29
  • Zuletzt bearbeitet 19.02.2026 19:26:43

Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored XSS via Entry Type names. The name is not sanitized when displayed in the Entry Types list. This vulnerability is fixed in 5.8.22.

  • EPSS 0.49%
  • Veröffentlicht 03.02.2026 22:16:22
  • Zuletzt bearbeitet 04.02.2026 16:33:44

CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code exec...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 05.01.2026 22:15:52
  • Zuletzt bearbeitet 12.01.2026 18:19:38

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations via specific admin actions, potentially leading to resource exhaustion...

Exploit
  • EPSS 1.13%
  • Veröffentlicht 05.01.2026 21:59:00
  • Zuletzt bearbeitet 12.01.2026 18:21:12

Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior. Note that attackers must have admin...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 05.01.2026 21:56:00
  • Zuletzt bearbeitet 12.01.2026 18:23:45

Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via Twig SSTI. For this to work, users must have administrator acces...

Exploit
  • EPSS 0.05%
  • Veröffentlicht 05.01.2026 21:52:29
  • Zuletzt bearbeitet 12.01.2026 18:28:14

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save_<VolumeName>_Asset` mutation is vulnerable to Server-Side Request Forgery (SSRF). This vulnerability...

  • EPSS 0.04%
  • Veröffentlicht 05.01.2026 21:46:01
  • Zuletzt bearbeitet 12.01.2026 18:29:17

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via malicious...

  • EPSS 0.32%
  • Veröffentlicht 25.08.2025 17:52:07
  • Zuletzt bearbeitet 03.09.2025 17:43:47

Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig SSTI (Server-Side Template Injection). This is a follow-up to CVE-2024-5...

  • EPSS 0.04%
  • Veröffentlicht 09.08.2025 01:31:23
  • Zuletzt bearbeitet 02.09.2025 19:23:07

Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass CVE-2025-23209: "Craft CMS has a potential RCE with a compromised security key". To exploit this vuln...