CVE-2026-44011
- EPSS 0.36%
- Veröffentlicht 12.05.2026 20:25:08
- Zuletzt bearbeitet 13.05.2026 16:16:53
Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an input-handling flaw in a Yii object creation path that let any authenticated user inject malicious configuration and execute arbitrar...
CVE-2026-44012
- EPSS 0.34%
- Veröffentlicht 12.05.2026 20:19:33
- Zuletzt bearbeitet 13.05.2026 14:54:50
Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() fetches an asset by ID and returns its filename and complete folder hierarchy (including volume handle, volume UID, folder names, ...
CVE-2026-44010
- EPSS 0.35%
- Veröffentlicht 12.05.2026 20:17:31
- Zuletzt bearbeitet 13.05.2026 16:16:53
Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element resolver (src/gql/resolvers/elements/Address.php) performs no schema scope filtering on top-level queries. A GraphQL API token scoped...
CVE-2026-41130
- EPSS 0.26%
- Veröffentlicht 21.04.2026 23:36:31
- Zuletzt bearbeitet 22.04.2026 20:26:20
Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources. When `trust...
CVE-2026-41129
- EPSS 0.28%
- Veröffentlicht 21.04.2026 23:34:56
- Zuletzt bearbeitet 22.04.2026 20:26:20
Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL s...
CVE-2026-41128
- EPSS 0.25%
- Veröffentlicht 21.04.2026 23:32:37
- Zuletzt bearbeitet 22.04.2026 20:26:20
Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces...
CVE-2026-33162
- EPSS 0.29%
- Veröffentlicht 24.03.2026 17:32:27
- Zuletzt bearbeitet 26.03.2026 20:41:41
Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/entries/move-to-section, even when they do not have...
CVE-2026-33161
- EPSS 0.22%
- Veröffentlicht 24.03.2026 17:31:28
- Zuletzt bearbeitet 26.03.2026 17:09:11
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can call assets/image-editor with the ID of a private asset they ...
CVE-2026-33160
- EPSS 0.36%
- Veröffentlicht 24.03.2026 17:30:20
- Zuletzt bearbeitet 26.03.2026 14:09:00
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, an unauthenticated user can call assets/generate-transform with a private assetId, receive a valid tr...
CVE-2026-33159
- EPSS 0.31%
- Veröffentlicht 24.03.2026 17:28:37
- Zuletzt bearbeitet 26.03.2026 17:08:48
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, guest users can access Config Sync updater index, obtain signed data, and execute state-changing Conf...