Craftcms Cms vulnerabilities

93 known vulnerabilities affecting craftcms/cms.

Total CVEs
93
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL8HIGH31MEDIUM50LOW4

Vulnerabilities

Page 3 of 5
CVE-2025-57811MEDIUMCVSS 6.1v>= 5.8.7, < 5.9.0-beta.1v>= 4.0.0-RC1, < 4.17.0-beta.12025-08-25
CVE-2025-57811 [MEDIUM] CWE-1336 CVE-2025-57811: Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig SSTI (Server-Side Template Injection). This is a follow-up to CVE-2024-52293. This vulnerability has been patched in versions 4.16.6 and 5.8.7.
cvelistv5ghsanvdosv
CVE-2025-54417HIGHCVSS 8.0v>= 4.13.8, < 4.16.3v>= 5.5.8, < 5.8.42025-08-09
CVE-2025-54417 [HIGH] CWE-94 Craft contains a theoretical bypass for CVE-2025-23209 Craft contains a theoretical bypass for CVE-2025-23209 Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass CVE-2025-23209: "Craft CMS has a potential RCE with a compromised security key". To exploit this vulnerability, the project must meet these requirements: have a compromised security key and create an arbitrary f
cvelistv5ghsaosv
CVE-2025-35939MEDIUMCVSS 6.9KEVv>= 4.15.3, < 4.17.3v>= 5.7.5, < 5.9.72025-05-07
CVE-2025-35939 [MEDIUM] CWE-472 CVE-2025-35939: Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file on the server at '/var/lib/php/sessions'. Such session files are named
ghsanvdosv
CVE-2025-46731HIGHCVSS 7.3v>= 4.0.0-RC1, < 4.14.13v>= 5.0.0-RC1, < 5.6.152025-05-05
CVE-2025-46731 [HIGH] CWE-1336 CVE-2025-46731: Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and o Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13
cvelistv5ghsanvdosv
CVE-2025-32432CRITICALCVSS 10.0KEVPoCv>= 3.0.0-RC1, < 3.9.15v>= 4.0.0-RC1, < 4.14.15+1 more2025-04-25
CVE-2025-32432 [CRITICAL] CWE-94 Craft CMS Allows Remote Code Execution Craft CMS Allows Remote Code Execution Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is
cvelistv5ghsaosv
CVE-2025-23209HIGHCVSS 8.1KEVv>= 4.13.8, < 4.16.3v>= 5.5.8, < 5.8.42025-01-18
CVE-2025-23209 [HIGH] CWE-94 CVE-2025-23209: Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security key is affected. This vulnerability
cvelistv5ghsanvdosv
CVE-2024-56145CRITICALCVSS 9.3KEVPoCv>= 4.0.0-RC1, < 4.13.2v>= 5.0.0-RC1, < 5.5.2+1 more2024-12-18
CVE-2024-56145 [CRITICAL] CWE-94 CVE-2024-56145: Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised to update to version 3.9.14, 4.
cvelistv5ghsanvdosv
CVE-2024-52291HIGHCVSS 7.2v>= 5.0.0-RC1, < 5.4.6v>= 4.0.0-RC1, < 4.12.52024-11-13
CVE-2024-52291 [HIGH] CWE-22 CVE-2024-52291: Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a double file:// scheme (e.g., file://file:////). This enables the attacker to specify sensitive folders as the file system, leading to potential file overwriting through malicious uploads, unauthorized access t
cvelistv5ghsanvdosv
CVE-2024-52293HIGHCVSS 7.2v>= 4.0.0-RC1, < 4.16.6v>= 5.0.0-RC1, < 5.8.72024-11-13
CVE-2024-52293 [HIGH] CWE-22 CVE-2024-52293: Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePat Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could lead to Remote Code Execution on the server via twig SSTI. This is a sequel to CVE-2023-40035. This vulnerability is fixed in 4.12.2 and 5.4.3.
cvelistv5ghsanvdosv
CVE-2024-52292MEDIUMCVSS 6.5v>= 5.0.0-alpha.1, < 5.4.9v>= 3.5.13, < 4.12.82024-11-13
CVE-2024-52292 [MEDIUM] CWE-22 CVE-2024-52292: Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, reads the file's content, and converts it into a Base64-encoded string. By embedding this function within a system notification template, the attacker can
cvelistv5ghsanvdosv
CVE-2024-45406MEDIUMCVSS 4.8v>= 5.0.0, < 5.1.22024-09-09
CVE-2024-45406 [MEDIUM] CWE-79 CVE-2024-45406: Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrum Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.
cvelistv5ghsanvdosv
CVE-2024-41800HIGHCVSS 7.5v>= 5.0.0-beta.1, < 5.2.32024-07-25
CVE-2024-41800 [HIGH] CWE-287 CVE-2024-41800: Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times w Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that the attacker has knowledge of the victim's credentials. This has been patched in Craft 5.2.3.
cvelistv5ghsanvdosv
CVE-2024-37843CRITICALPoC≥ 0, ≤ 3.7.312024-06-25
CVE-2024-37843 [CRITICAL] CWE-89 Craft CMS SQL injection vulnerability via the GraphQL API endpoint Craft CMS SQL injection vulnerability via the GraphQL API endpoint Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
ghsaosv
CVE-2023-36260HIGH≥ 0, < 4.6.22024-01-30
CVE-2023-36260 [HIGH] CWE-74 Craft CMS Feed-Me Craft CMS Feed-Me An issue discovered in Craft CMS version 4.6.1.1 allows remote attackers to cause a denial of service (DoS) via crafted string to Feed-Me Name and Feed-Me URL fields due to saving a feed using an Asset element type with no volume selected.
ghsaosv
CVE-2024-21622HIGHCVSS 8.8v>= 4.0.0-RC1, < 4.5.11v>= 3.0.0, < 3.9.62024-01-03
CVE-2024-21622 [HIGH] CWE-269 CVE-2024-21622: Craft is a content management system. This is a potential moderate impact, low complexity privilege Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. This has been fixed in Craft 4.4.16 and Craft 3.9.6. Users should ensure they are running at least those versions.
cvelistv5ghsanvdosv
CVE-2023-41892CRITICALCVSS 9.8PoCv>= 3.0.0-RC1, < 3.9.15v>= 4.0.0-RC1, < 4.14.15+1 more2023-09-13
CVE-2023-41892 [CRITICAL] CWE-94 CVE-2023-41892: Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity atta Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.
cvelistv5ghsanvdosv
CVE-2023-40035HIGHCVSS 7.2v>= 4.0.0-RC1, < 4.12.2v>= 5.0.0-RC1, < 5.4.32023-08-23
CVE-2023-40035 [HIGH] CWE-74 CVE-2023-40035: Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validate Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code execution. This vulnerability can lead to malicious control of vulnerable systems and data exfiltrations. Although the vulnerability is exploitable only in the authenticated users, configuration with ALLOW_
cvelistv5ghsanvdosv
CVE-2023-33495MEDIUM≥ 0, ≤ 4.4.92023-06-20
CVE-2023-33495 [MEDIUM] CWE-79 Craft CMS vulnerable to HTML injection Craft CMS vulnerable to HTML injection Craft CMS through 4.4.9 is vulnerable to HTML Injection.
ghsaosv
CVE-2023-30179HIGH≥ 0, < 4.4.22023-06-13
CVE-2023-30179 [HIGH] CWE-94 Withdrawn Advisory: CraftCMS Server-Side Template Injection vulnerability Withdrawn Advisory: CraftCMS Server-Side Template Injection vulnerability ## Withdrawn This advisory has been withdrawn because the CVE has been disputed and the underlying vulnerability is likely invalid. This link is maintained to preserve external references. [According to maintainers of Craft CMS](https://github.com/github/advisory-database/pull/2443#issuecomment-1610634200), only adminis
ghsa
CVE-2023-33195MEDIUMCVSS 6.1v>= 4.3.0, <= 4.4.52023-05-27
CVE-2023-33195 [MEDIUM] CWE-79 CVE-2023-33195: Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This issue was patched in version 4.4.6.
cvelistv5ghsanvdosv