CVE-2020-19626
- EPSS 0.23%
- Veröffentlicht 26.03.2021 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:09:17
Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new.
CVE-2020-9757
- EPSS 94.28%
- Veröffentlicht 04.03.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:41:13
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.
CVE-2019-9554
- EPSS 1.55%
- Veröffentlicht 31.12.2019 17:15:11
- Zuletzt bearbeitet 21.11.2024 04:51:50
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.
CVE-2019-15929
- EPSS 0.36%
- Veröffentlicht 24.10.2019 16:15:20
- Zuletzt bearbeitet 21.11.2024 04:29:45
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
CVE-2019-17496
- EPSS 0.33%
- Veröffentlicht 11.10.2019 00:15:10
- Zuletzt bearbeitet 21.11.2024 04:32:22
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
CVE-2019-14280
- EPSS 15.9%
- Veröffentlicht 26.07.2019 04:15:11
- Zuletzt bearbeitet 21.11.2024 04:26:21
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
CVE-2019-12823
- EPSS 0.29%
- Veröffentlicht 18.06.2019 13:15:10
- Zuletzt bearbeitet 21.11.2024 04:23:39
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
CVE-2018-20465
- EPSS 0.2%
- Veröffentlicht 25.12.2018 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:32
Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of th...
CVE-2018-20418
- EPSS 0.47%
- Veröffentlicht 24.12.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 04:01:26
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
CVE-2018-3814
- EPSS 0.7%
- Veröffentlicht 01.01.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:06:05
Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option, because this allows a .jpg file to have embedded PHP code, and then be renamed to a .php extension.