Craftcms

Craft Cms

75 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 89.54%
  • Veröffentlicht 25.06.2024 21:15:59
  • Zuletzt bearbeitet 21.11.2024 09:24:22

Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.

  • EPSS 0.48%
  • Veröffentlicht 30.01.2024 09:15:47
  • Zuletzt bearbeitet 21.11.2024 08:09:28

An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings to Feed-Me Name and Feed-Me URL fields, due to saving a feed using an Asset element type with no volu...

  • EPSS 0.09%
  • Veröffentlicht 30.01.2024 09:15:47
  • Zuletzt bearbeitet 29.05.2025 15:15:24

Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation.

  • EPSS 0.1%
  • Veröffentlicht 03.01.2024 17:15:12
  • Zuletzt bearbeitet 21.11.2024 08:54:44

Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. This has been fixed in ...

  • EPSS 93.91%
  • Veröffentlicht 13.09.2023 20:15:08
  • Zuletzt bearbeitet 21.11.2024 08:21:52

Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has bee...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 23.08.2023 21:15:08
  • Zuletzt bearbeitet 21.11.2024 08:18:34

Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code execution. This vulnerability can lead to malicious control of vulnerable systems and data exfiltratio...

  • EPSS 0.18%
  • Veröffentlicht 20.06.2023 13:15:09
  • Zuletzt bearbeitet 09.12.2024 22:15:21

Craft CMS through 4.4.9 is vulnerable to HTML Injection.

Exploit
  • EPSS 4.16%
  • Veröffentlicht 13.06.2023 17:15:14
  • Zuletzt bearbeitet 03.01.2025 20:15:25

CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution. NOTE: th...

Exploit
  • EPSS 0.51%
  • Veröffentlicht 27.05.2023 04:15:25
  • Zuletzt bearbeitet 21.11.2024 08:05:05

Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This issue was patched in version 4.4.6.

Exploit
  • EPSS 0.09%
  • Veröffentlicht 26.05.2023 21:15:21
  • Zuletzt bearbeitet 21.11.2024 08:05:06

Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.