Craftcms

Craft Cms

75 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Warnung Medienbericht
  • EPSS 27.62%
  • Veröffentlicht 07.05.2025 22:41:29
  • Zuletzt bearbeitet 24.10.2025 13:45:43

Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login pag...

  • EPSS 0.91%
  • Veröffentlicht 05.05.2025 19:35:31
  • Zuletzt bearbeitet 03.09.2025 18:06:16

Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW...

Medienbericht Exploit
  • EPSS 82%
  • Veröffentlicht 25.04.2025 15:04:06
  • Zuletzt bearbeitet 28.04.2025 20:57:06

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code ex...

Warnung
  • EPSS 19.13%
  • Veröffentlicht 18.01.2025 01:15:07
  • Zuletzt bearbeitet 24.10.2025 13:59:53

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyon...

Warnung Medienbericht Exploit
  • EPSS 94.05%
  • Veröffentlicht 18.12.2024 21:15:08
  • Zuletzt bearbeitet 24.10.2025 14:00:03

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an un...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 13.11.2024 17:15:12
  • Zuletzt bearbeitet 19.11.2024 18:27:21

Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, reads the file's content, and converts it into a Bas...

Exploit
  • EPSS 0.09%
  • Veröffentlicht 13.11.2024 17:15:12
  • Zuletzt bearbeitet 19.11.2024 18:06:42

Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a double file:// scheme (e.g., file://file:////). This enables the attacker to specify sensitive folders as...

Exploit
  • EPSS 17.44%
  • Veröffentlicht 13.11.2024 16:15:19
  • Zuletzt bearbeitet 19.11.2024 17:51:39

Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could lead to Remote Code Execution on the server via twig SSTI. This is a sequel to CVE-2023-40035. This v...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 09.09.2024 17:15:13
  • Zuletzt bearbeitet 13.09.2024 15:30:45

Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.

  • EPSS 0.34%
  • Veröffentlicht 25.07.2024 17:15:11
  • Zuletzt bearbeitet 21.11.2024 09:33:05

Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that the attacker ...