Craftcms

Craft Cms

124 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 10.03.2026 19:44:44
  • Zuletzt bearbeitet 12.03.2026 15:36:11

Craft is a content management system (CMS). Prior to 4.17.4 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action does not requ...

  • EPSS 0.27%
  • Veröffentlicht 04.03.2026 17:16:22
  • Zuletzt bearbeitet 05.03.2026 10:40:07

Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() endpoint is accessible to unauthenticated users and does not require a permission check for pending users. An attacker with no prior ...

  • EPSS 0.46%
  • Veröffentlicht 04.03.2026 17:16:21
  • Zuletzt bearbeitet 05.03.2026 20:24:42

Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerous PHP functions from being called via Twig non-Closure arrow functions. In order to be able to succes...

  • EPSS 0.53%
  • Veröffentlicht 04.03.2026 17:16:21
  • Zuletzt bearbeitet 05.03.2026 10:37:57

Craft is a content management system (CMS). Prior to 5.8.22 and 4.16.18, it is possible to craft a malicious payload using the Twig map filter in text fields that accept Twig input under Settings in the Craft control panel or using the System Message...

Exploit
  • EPSS 0.23%
  • Veröffentlicht 04.03.2026 16:36:49
  • Zuletzt bearbeitet 05.03.2026 19:55:33

Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, the "Duplicate" entry action does not properly verify if the user has permission to perform this action on the specific target elements. Even with only "View Entries...

Exploit
  • EPSS 0.33%
  • Veröffentlicht 04.03.2026 16:31:39
  • Zuletzt bearbeitet 05.03.2026 19:55:03

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the authorId attribute. A user with "Create Entries" permission can inject the authorIds[] (or authorId) par...

Exploit
  • EPSS 1.07%
  • Veröffentlicht 04.03.2026 16:26:37
  • Zuletzt bearbeitet 05.03.2026 10:37:46

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fields (e.g., ...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 04.03.2026 16:21:43
  • Zuletzt bearbeitet 05.03.2026 19:54:51

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal reference tags (e.g., {user:1:email}), can be abused by both authenticated users and unauthenticated gue...

Exploit
  • EPSS 0.56%
  • Veröffentlicht 04.03.2026 16:15:32
  • Zuletzt bearbeitet 05.03.2026 19:54:27

Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Template Injection using the create() Twig function combined with a Symfony Process gadget chain. The create() Twig function exposes C...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 24.02.2026 02:45:45
  • Zuletzt bearbeitet 02.03.2026 20:35:37

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation uses `gethostbyname()`, which only resolves IPv4 addresses. When a hostname has ...