CVE-2026-31858
- EPSS 0.35%
- Veröffentlicht 11.03.2026 17:35:07
- Zuletzt bearbeitet 17.03.2026 14:05:38
Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() protection that was added to ElementIndexesController in CVE-2026-25495. The exact same SQL injection vulnerability (including cri...
CVE-2026-31857
- EPSS 0.67%
- Veröffentlicht 11.03.2026 17:30:29
- Zuletzt bearbeitet 17.03.2026 14:15:46
Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The BaseElementSelectConditionRule::getElementIds() method passes user-controlled string input t...
CVE-2026-29113
- EPSS 0.17%
- Veröffentlicht 10.03.2026 19:44:44
- Zuletzt bearbeitet 02.09.2026 14:17:11
Craft is a content management system (CMS). Prior to 4.17.3 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action does not requ...
CVE-2026-29069
- EPSS 0.27%
- Veröffentlicht 04.03.2026 17:16:22
- Zuletzt bearbeitet 05.03.2026 10:40:07
Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() endpoint is accessible to unauthenticated users and does not require a permission check for pending users. An attacker with no prior ...
CVE-2026-28783
- EPSS 0.46%
- Veröffentlicht 04.03.2026 17:16:21
- Zuletzt bearbeitet 05.03.2026 20:24:42
Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerous PHP functions from being called via Twig non-Closure arrow functions. In order to be able to succes...
CVE-2026-28784
- EPSS 0.53%
- Veröffentlicht 04.03.2026 17:16:21
- Zuletzt bearbeitet 05.03.2026 10:37:57
Craft is a content management system (CMS). Prior to 5.8.22 and 4.16.18, it is possible to craft a malicious payload using the Twig map filter in text fields that accept Twig input under Settings in the Craft control panel or using the System Message...
CVE-2026-28782
- EPSS 0.23%
- Veröffentlicht 04.03.2026 16:36:49
- Zuletzt bearbeitet 05.03.2026 19:55:33
Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, the "Duplicate" entry action does not properly verify if the user has permission to perform this action on the specific target elements. Even with only "View Entries...
CVE-2026-28781
- EPSS 0.33%
- Veröffentlicht 04.03.2026 16:31:39
- Zuletzt bearbeitet 05.03.2026 19:55:03
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the authorId attribute. A user with "Create Entries" permission can inject the authorIds[] (or authorId) par...
CVE-2026-28697
- EPSS 1.07%
- Veröffentlicht 04.03.2026 16:26:37
- Zuletzt bearbeitet 05.03.2026 10:37:46
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fields (e.g., ...
CVE-2026-28696
- EPSS 0.45%
- Veröffentlicht 04.03.2026 16:21:43
- Zuletzt bearbeitet 05.03.2026 19:54:51
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal reference tags (e.g., {user:1:email}), can be abused by both authenticated users and unauthenticated gue...