CVE-2026-33158
- EPSS 0.35%
- Veröffentlicht 24.03.2026 17:26:03
- Zuletzt bearbeitet 26.03.2026 17:08:28
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can read private asset content by calling assets/edit-image with ...
CVE-2026-33157
- EPSS 1.02%
- Veröffentlicht 24.03.2026 17:22:00
- Zuletzt bearbeitet 26.03.2026 17:08:13
Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.13, a Remote Code Execution (RCE) vulnerability exists in Craft CMS, it can be exploited by any authenticated user with control panel access. This is a bypass of...
CVE-2026-33051
- EPSS 0.24%
- Veröffentlicht 20.03.2026 05:56:02
- Zuletzt bearbeitet 20.03.2026 19:37:28
Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor renders the creator’s fullName as raw HTML due to the use of Template::raw() combined with Craft::t() strin...
CVE-2026-32267
- EPSS 7.73%
- Veröffentlicht 16.03.2026 19:04:47
- Zuletzt bearbeitet 17.03.2026 17:44:31
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their p...
CVE-2026-32264
- EPSS 0.52%
- Veröffentlicht 16.03.2026 19:02:22
- Zuletzt bearbeitet 17.03.2026 17:53:45
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, there is a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController. Cra...
CVE-2026-32263
- EPSS 0.5%
- Veröffentlicht 16.03.2026 18:57:50
- Zuletzt bearbeitet 17.03.2026 17:55:32
Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTypesController.php, the $settings array from parse_str is passed directly to Craft::configure() without Component::cleanseConfig(). ...
CVE-2026-32262
- EPSS 0.29%
- Veröffentlicht 16.03.2026 18:57:46
- Zuletzt bearbeitet 17.03.2026 17:56:54
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, the AssetsController->replaceFile() method has a targetFilename body parameter that is used unsanitiz...
CVE-2026-31859
- EPSS 0.19%
- Veröffentlicht 11.03.2026 17:37:19
- Zuletzt bearbeitet 17.03.2026 14:03:57
Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize return URLs before they are stored in the session. However, strip_tags() only removes HTML tags (ang...
CVE-2026-31858
- EPSS 0.35%
- Veröffentlicht 11.03.2026 17:35:07
- Zuletzt bearbeitet 17.03.2026 14:05:38
Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() protection that was added to ElementIndexesController in CVE-2026-25495. The exact same SQL injection vulnerability (including cri...
CVE-2026-31857
- EPSS 0.67%
- Veröffentlicht 11.03.2026 17:30:29
- Zuletzt bearbeitet 17.03.2026 14:15:46
Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The BaseElementSelectConditionRule::getElementIds() method passes user-controlled string input t...