Craftcms

Craft Cms

124 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.31%
  • Veröffentlicht 09.02.2026 19:25:29
  • Zuletzt bearbeitet 19.02.2026 19:26:43

Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored XSS via Entry Type names. The name is not sanitized when displayed in the Entry Types list. This vulnerability is fixed in 5.8.22.

  • EPSS 0.62%
  • Veröffentlicht 03.02.2026 22:16:22
  • Zuletzt bearbeitet 15.04.2026 00:35:42

CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code exec...

Exploit
  • EPSS 0.49%
  • Veröffentlicht 05.01.2026 22:15:52
  • Zuletzt bearbeitet 12.01.2026 18:19:38

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations via specific admin actions, potentially leading to resource exhaustion...

Exploit
  • EPSS 0.83%
  • Veröffentlicht 05.01.2026 21:59:00
  • Zuletzt bearbeitet 12.01.2026 18:21:12

Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior. Note that attackers must have admin...

Exploit
  • EPSS 0.82%
  • Veröffentlicht 05.01.2026 21:56:00
  • Zuletzt bearbeitet 12.01.2026 18:23:45

Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via Twig SSTI. For this to work, users must have administrator acces...

Exploit
  • EPSS 0.44%
  • Veröffentlicht 05.01.2026 21:52:29
  • Zuletzt bearbeitet 12.01.2026 18:28:14

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save_<VolumeName>_Asset` mutation is vulnerable to Server-Side Request Forgery (SSRF). This vulnerability...

  • EPSS 0.24%
  • Veröffentlicht 05.01.2026 21:46:01
  • Zuletzt bearbeitet 12.01.2026 18:29:17

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via malicious...

  • EPSS 0.86%
  • Veröffentlicht 25.08.2025 17:52:07
  • Zuletzt bearbeitet 03.09.2025 17:43:47

Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig SSTI (Server-Side Template Injection). This is a follow-up to CVE-2024-5...

  • EPSS 0.49%
  • Veröffentlicht 09.08.2025 01:31:23
  • Zuletzt bearbeitet 02.09.2025 19:23:07

Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass CVE-2025-23209: "Craft CMS has a potential RCE with a compromised security key". To exploit this vuln...

Warnung Medienbericht
  • EPSS 1.32%
  • Veröffentlicht 07.05.2025 22:41:29
  • Zuletzt bearbeitet 24.10.2025 13:45:43

Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login pag...