Craftcms

Craft Cms

146 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.2%
  • Veröffentlicht 02.09.2026 11:11:10
  • Zuletzt bearbeitet 04.09.2026 03:17:45

Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of confl...

  • EPSS 1%
  • Veröffentlicht 24.08.2026 15:36:07
  • Zuletzt bearbeitet 28.08.2026 16:08:09

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii beh...

  • EPSS 0.33%
  • Veröffentlicht 12.08.2026 19:07:35
  • Zuletzt bearbeitet 31.08.2026 20:38:54

Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission can reset any user's password i...

  • EPSS 0.19%
  • Veröffentlicht 11.08.2026 12:17:19
  • Zuletzt bearbeitet 28.08.2026 18:45:00

Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can permanently modify that group's category structure...

  • EPSS 0.15%
  • Veröffentlicht 11.08.2026 12:17:18
  • Zuletzt bearbeitet 08.09.2026 20:32:39

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<Volume>Asset mutation, which fetches an attacker-supplied URL server-side. The anti-SSRF validation i...

  • EPSS 0.23%
  • Veröffentlicht 11.08.2026 12:17:17
  • Zuletzt bearbeitet 28.08.2026 18:45:00

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (via ${ENV_VAR} strings in the elementId parameter) into Twig templates before rendering, even when the Twig sandbox is enabled...

  • EPSS 0.54%
  • Veröffentlicht 11.08.2026 12:17:16
  • Zuletzt bearbeitet 08.09.2026 20:32:39

Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechanism. Because Craft marks the ElementInterface as safe (via the AllowedInSandbox attribute) and the sa...

  • EPSS 0.23%
  • Veröffentlicht 11.08.2026 12:17:15
  • Zuletzt bearbeitet 28.08.2026 18:45:00

Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can replay captured login request bodies containing requestOptions and response to create additional aut...

  • EPSS 0.45%
  • Veröffentlicht 11.08.2026 12:17:14
  • Zuletzt bearbeitet 26.08.2026 16:57:52

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. Craft cleanses the outer request-controlled conditio...

  • EPSS 0.22%
  • Veröffentlicht 11.08.2026 12:17:14
  • Zuletzt bearbeitet 08.09.2026 20:32:39

Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create() Twig function restricts class instantiation using a 5-entry blocklist that does not include SplFileObject, allowing an authentica...