CVE-2026-28697
- EPSS 0.18%
- Veröffentlicht 04.03.2026 16:26:37
- Zuletzt bearbeitet 05.03.2026 10:37:46
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fields (e.g., ...
CVE-2026-28696
- EPSS 0.02%
- Veröffentlicht 04.03.2026 16:21:43
- Zuletzt bearbeitet 05.03.2026 19:54:51
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal reference tags (e.g., {user:1:email}), can be abused by both authenticated users and unauthenticated gue...
CVE-2026-28695
- EPSS 0.07%
- Veröffentlicht 04.03.2026 16:15:32
- Zuletzt bearbeitet 05.03.2026 19:54:27
Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Template Injection using the create() Twig function combined with a Symfony Process gadget chain. The create() Twig function exposes C...
CVE-2026-27129
- EPSS 0.01%
- Veröffentlicht 24.02.2026 02:45:45
- Zuletzt bearbeitet 02.03.2026 20:35:37
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation uses `gethostbyname()`, which only resolves IPv4 addresses. When a hostname has ...
CVE-2026-27128
- EPSS 0.01%
- Veröffentlicht 24.02.2026 02:42:53
- Zuletzt bearbeitet 27.02.2026 20:06:52
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a Time-of-Check-Time-of-Use (TOCTOU) race condition exists in Craft CMS’s token validation service for tokens that explicitly set a limite...
CVE-2026-27127
- EPSS 0.01%
- Veröffentlicht 24.02.2026 02:39:44
- Zuletzt bearbeitet 25.02.2026 19:31:05
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation performs DNS resolution separately from the HTTP request. This Time-of-Check-Tim...
CVE-2026-27126
- EPSS 0.01%
- Veröffentlicht 24.02.2026 02:30:04
- Zuletzt bearbeitet 27.02.2026 20:06:03
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a stored Cross-site Scripting (XSS) vulnerability exists in the `editableTable.twig` component when using the `html` column type. The appl...
CVE-2026-25498
- EPSS 0.3%
- Veröffentlicht 09.02.2026 19:55:06
- Zuletzt bearbeitet 19.02.2026 19:20:46
Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a Remote Code Execution (RCE) vulnerability exists in Craft CMS where the assembleLayoutFromPost() function in src/services/Fiel...
CVE-2026-25497
- EPSS 0.02%
- Veröffentlicht 09.02.2026 19:50:08
- Zuletzt bearbeitet 19.02.2026 19:16:05
Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege Escalation vulnerability in Craft CMS’s GraphQL API that allows an authenticated user with write acc...
CVE-2026-25496
- EPSS 0.02%
- Veröffentlicht 09.02.2026 19:45:19
- Zuletzt bearbeitet 19.02.2026 19:17:02
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a stored XSS vulnerability exists in the Number field type settings. The Prefix and Suffix fields are rendered using the |...