CVE-2022-37783
- EPSS 0.56%
- Veröffentlicht 05.12.2022 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:15:09
All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_T...
CVE-2022-37246
- EPSS 0.31%
- Veröffentlicht 21.09.2022 15:15:14
- Zuletzt bearbeitet 27.05.2025 19:15:22
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
CVE-2022-37251
- EPSS 0.31%
- Veröffentlicht 16.09.2022 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:14:40
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.
CVE-2022-37247
- EPSS 0.31%
- Veröffentlicht 16.09.2022 22:15:12
- Zuletzt bearbeitet 21.11.2024 07:14:39
Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.
CVE-2022-37248
- EPSS 0.31%
- Veröffentlicht 16.09.2022 16:15:10
- Zuletzt bearbeitet 21.11.2024 07:14:39
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.
CVE-2022-37250
- EPSS 0.31%
- Veröffentlicht 16.09.2022 15:15:09
- Zuletzt bearbeitet 03.06.2025 18:15:22
Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.
CVE-2022-29933
- EPSS 2.32%
- Veröffentlicht 09.05.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:59:59
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the password reset f...
CVE-2022-28378
- EPSS 0.33%
- Veröffentlicht 03.04.2022 18:15:07
- Zuletzt bearbeitet 21.11.2024 06:57:15
Craft CMS before 3.7.29 allows XSS.
CVE-2021-41824
- EPSS 0.51%
- Veröffentlicht 30.09.2021 00:15:07
- Zuletzt bearbeitet 21.11.2024 06:26:49
Craft CMS before 3.7.14 allows CSV injection.
CVE-2021-27903
- EPSS 3.82%
- Veröffentlicht 30.06.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 05:58:44
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's ses...