Craftcms Cms vulnerabilities
148 known vulnerabilities affecting craftcms/cms.
Total CVEs
148
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL11HIGH54MEDIUM83
Vulnerabilities
Page 1 of 8
CVE-2024-56145P1CRITICALCVSS 9.8KEVPoCv>= 4.0.0-RC1, < 4.13.2v>= 5.0.0-RC1, < 5.5.2+1 more2024-12-18
CVE-2024-56145 [CRITICAL] CWE-94 CVE-2024-56145: Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised to update to version 3.9.14, 4.
ghsanvdosv
CVE-2025-32432P1CRITICALKEVPoC≥ 3.0.0-RC1, < 3.9.15≥ 4.0.0-RC1, < 4.14.15+1 more2025-04-25
CVE-2025-32432 [CRITICAL] CWE-94 Craft CMS Allows Remote Code Execution
Craft CMS Allows Remote Code Execution
### Impact
This is an additional fix for https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25g
This is a high-impact, low-complexity attack vector. To mitigate the issue, users running Craft installations before the fixed versions are encouraged to update to at least that version.
### Details
https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432
### Refere
ghsaosv
CVE-2025-23209P1HIGHCVSS 8.1KEVv>= 4.13.8, < 4.16.3v>= 5.5.8, < 5.8.42025-01-18
CVE-2025-23209 [HIGH] CWE-94 CVE-2025-23209: Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security key is affected. This vulnerability
ghsanvdosv
CVE-2025-35939P1MEDIUMCVSS 5.3KEVv>= 4.15.3, < 4.17.3v>= 5.7.5, < 5.9.72025-05-07
CVE-2025-35939 [MEDIUM] CWE-472 CVE-2025-35939: Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content
Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file on the server at '/var/lib/php/sessions'. Such session files are named
ghsanvdosv
CVE-2023-41892P1CRITICALCVSS 9.8ExploitedPoCv>= 3.0.0-RC1, < 3.9.15v>= 4.0.0-RC1, < 4.14.15+1 more2023-09-13
CVE-2023-41892 [CRITICAL] CWE-94 CVE-2023-41892: Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity atta
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.
ghsanvdosv
CVE-2024-37843P2CRITICALPoC≥ 0, ≤ 3.7.312024-06-25
CVE-2024-37843 [CRITICAL] CWE-89 Craft CMS SQL injection vulnerability via the GraphQL API endpoint
Craft CMS SQL injection vulnerability via the GraphQL API endpoint
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
ghsaosv
CVE-2026-32267P2CRITICALCVSS 9.8v>= 4.0.0-RC1, < 4.17.6v>= 5.0.0-RC1, < 5.9.122026-03-16
CVE-2026-32267 [CRITICAL] CWE-863 CVE-2026-32267: Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their privileges to admin by abusing UsersController->actionImpersonateWithToken. This issue has been patch
ghsanvdosv
CVE-2026-72781P2HIGHCVSS 8.8≥ 5.0.0-RC1, < 5.10.7≥ 4.0.0-RC1, < 4.18.32026-08-11
CVE-2026-72781 [HIGH] CWE-693 CVE-2026-72781: Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code e
Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechanism. Because Craft marks the ElementInterface as safe (via the AllowedInSandbox attribute) and the sandbox allowlisting extends to the entire class hierarchy (craft\base\Component up to yii\base\Component
nvd
CVE-2025-68454P2HIGHCVSS 8.8v>= 5.0.0-RC1, < 5.8.21v>= 4.0.0-RC1, < 4.16.172026-01-05
CVE-2025-68454 [HIGH] CWE-1336 CVE-2025-68454: Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC
Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via Twig SSTI. For this to work, users must have administrator access to the Craft Control Panel, and allowAdminChanges must be enabled, which is against Craft CMS' recom
ghsanvdosv
CVE-2026-25495P2HIGHCVSS 8.8v>= 5.0.0-RC1, <= 5.9.82026-02-09
CVE-2026-25495 [HIGH] CWE-89 CVE-2026-25495: Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 an
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/get-elements endpoint is vulnerable to SQL Injection via the criteria[orderBy] parameter (JSON body). The application fails to sanitize this input before using it in the database query. An attacker with Con
ghsanvdosv
CVE-2026-86732P2HIGHCVSS 8.8≥ 5.0.0-RC1, < 5.10.122026-09-08
CVE-2026-86732 [HIGH] CWE-94 CVE-2026-86732: Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index
Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter. Attackers can inject a malicious class via criteria[withTransforms][0][class] that reaches ImageTransforms::normalizeTransform(), then us
nvd
CVE-2026-86730P2HIGHCVSS 8.8≥ 5.0.0-RC1, < 5.10.122026-09-08
CVE-2026-86730 [HIGH] CWE-94 CVE-2026-86730: Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allow
Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON strings to bypass cleanse validation, then trigger arbitrary object instantiation and code execution throug
nvd
CVE-2026-72778P2HIGHCVSS 8.8≥ 5.0.0-RC1, < 5.10.6≥ 4.0.0-RC1, < 4.18.22026-08-11
CVE-2026-72778 [HIGH] CWE-915 CVE-2026-72778: Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenti
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. Craft cleanses the outer request-controlled condition array via Component::cleanseConfig(), but Conditions::createCondition() later decodes and merges the
nvd
CVE-2026-78416P2HIGHCVSS 8.7≥ 4.0.0-RC1, < 4.18.2≥ 5.0.0-RC1, < 5.10.62026-08-24
CVE-2026-78416 [HIGH] CWE-915 CVE-2026-78416: Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenti
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior/event configuration keys to be interpreted after decoding, enabling command execution as the PHP/
nvd
CVE-2026-28697P2CRITICALCVSS 9.1v>= 5.0.0-RC1, < 5.9.0-beta.1v>= 4.0.0-RC1, < 4.17.0-beta.12026-03-04
CVE-2026-28697 [CRITICAL] CWE-1336 CVE-2026-28697: Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticate
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fields (e.g., Email Templates). By calling the craft.app.fs.write() method, an attacker can write a malicious PH
ghsanvdosv
CVE-2026-31857P2HIGHCVSS 8.8v>= 5.0.0-RC1, < 5.9.9v>= 4.0.0-beta.1, < 4.17.42026-03-11
CVE-2026-31857 [HIGH] CWE-94 CVE-2026-31857: Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulne
Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The BaseElementSelectConditionRule::getElementIds() method passes user-controlled string input through renderObjectTemplate() -- an unsandboxed Twig rendering function with escaping disabled. Any auth
ghsanvdosv
CVE-2026-25497P3HIGHCVSS 8.8v>= 5.0.0-RC1, < 5.8.22v>= 4.0.0-RC1, < 4.17.0-beta.12026-02-09
CVE-2026-25497 [HIGH] CWE-639 CVE-2026-25497: Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.1
Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege Escalation vulnerability in Craft CMS’s GraphQL API that allows an authenticated user with write access to one asset volume to escalate their privileges and modify/transfer assets belonging to any other
ghsanvdosv
CVE-2026-79989P3HIGHCVSS 8.7≥ 5.0.0-RC1, < 5.10.82026-09-02
CVE-2026-79989 [HIGH] CWE-285 CVE-2026-79989: The vulnerability allows any authenticated user to change their own password without providing the c
The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users’ passwords if the attacker’s account has Edit users permission (which doesn’t allow changing others’ passwords) and lacks Administrate users permissi
nvd
CVE-2025-54417P3HIGHCVSS 8.1≥ 4.13.8, < 4.16.3≥ 5.5.8, < 5.8.42025-08-08
CVE-2025-54417 [HIGH] CWE-94 Craft CMS has a theoretical bypass for CVE-2025-23209
Craft CMS has a theoretical bypass for CVE-2025-23209
**Pre-requisites:**
* Have a compromised security key (https://craftcms.com/knowledge-base/securing-craft#keep-your-secrets-secret)
* Somehow, manage to create an arbitrary file in Craft’s `/storage/backups` folder.
With those two pieces in place, you could create a specific, malicious request to the `/updater/restore-db` endpoint to execute CLI commands rem
ghsaosv
CVE-2026-84801P3HIGHCVSS 8.8≥ 5.0.0-RC1, < 5.10.112026-09-02
CVE-2026-84801 [HIGH] CWE-862 CVE-2026-84801: Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl end
Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator accounts. Attackers can generate a valid reset URL for any admin user and set a new password via actionSetPassword, which validates only the
nvd
1 / 8Next →