cbcvebase.

Craftcms Cms vulnerabilities

148 known vulnerabilities affecting craftcms/cms.

Total CVEs
148
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL11HIGH54MEDIUM83

Vulnerabilities

Page 4 of 8
CVE-2024-52292P3MEDIUMCVSS 6.5v>= 5.0.0-alpha.1, < 5.4.9v>= 3.5.13, < 4.12.82024-11-13
CVE-2024-52292 [MEDIUM] CWE-22 CVE-2024-52292: Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, reads the file's content, and converts it into a Base64-encoded string. By embedding this function within a system notification template, the attacker can
ghsanvdosv
CVE-2026-56394P3MEDIUMCVSS 6.5≥ 4.0.0-RC1, < 4.17.7≥ 5.0.0-RC1, < 5.9.132026-06-21
CVE-2026-56394 [MEDIUM] CWE-22 CVE-2026-56394: Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon e Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing traversal sequences that resolve to existing SVG files, allowing local file read access.
nvd
CVE-2026-55790P3HIGHCVSS 7.4v>= 5.0.0-RC1, < 5.9.23v>= 4.0.0-RC1, < 4.17.162026-07-01
CVE-2026-55790 [HIGH] CWE-79 CVE-2026-55790: Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22 and 4.0.0-RC1 t Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22 and 4.0.0-RC1 through 4.17.15, an attacker with only a GitHub account can plant a JavaScript payload in a craftcms/cms issue title. When a Craft admin uses the CraftSupport widget’s "Give feedback" screen and types a search term that returns the poisoned issue, the pay
ghsanvd
CVE-2026-27127P3MEDIUMCVSS 5.0≥ 5.0.0-RC1, < 5.8.23≥ 3.5.0, < 4.16.192026-02-23
CVE-2026-27127 [MEDIUM] CWE-367 Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding ## Summary The SSRF validation in Craft CMS’s GraphQL Asset mutation performs DNS resolution **separately** from the HTTP request. This Time-of-Check-Time-of-Use (TOCTOU) vulnerability enables DNS rebinding attacks, where an attacker’s DNS server returns different IP addresses for validation compared to the actual request.
ghsaosv
CVE-2026-50281P3HIGHCVSS 7.1v>= 5.7.0, < 5.9.212026-07-02
CVE-2026-50281 [HIGH] CWE-915 CVE-2026-50281: Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw in the bulk-duplicate element action. An attacker who is only able to duplicate their own entires can submit an arbitrary id through the newAttributes request parameter. The duplication routine overrides its own id = null reset with
ghsanvd
CVE-2026-84797P3MEDIUMCVSS 6.3≥ 5.0.0-RC1, < 5.10.112026-09-02
CVE-2026-84797 [MEDIUM] CWE-862 CVE-2026-84797: Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsControlle Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows authenticated users with createEntries permission to delete peer provisional drafts. Attackers can exploit the deleteProvisionalDraft parameter to delete another user's unsaved draft without proper authorization checks
nvd
CVE-2026-27129P3MEDIUMCVSS 5.0≥ 5.0.0-RC1, < 5.8.23≥ 3.5.0, < 4.16.192026-02-24
CVE-2026-27129 [MEDIUM] CWE-918 Craft CMS: Cloud Metadata SSRF Protection Bypass via IPv6 Resolution Craft CMS: Cloud Metadata SSRF Protection Bypass via IPv6 Resolution The SSRF validation in Craft CMS’s GraphQL Asset mutation uses `gethostbyname()`, which only resolves IPv4 addresses. When a hostname has only AAAA (IPv6) records, the function returns the hostname string itself, causing the blocklist comparison to always fail and completely bypassing SSRF protection. This is a bypass of the s
ghsaosv
CVE-2026-84798P3HIGHCVSS 7.1≥ 5.0.0-RC1, < 5.10.112026-09-02
CVE-2026-84798 [HIGH] CWE-862 CVE-2026-84798: Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element with checkForProvisionalDraft enabled and runs the deletion authorization check against the user's own provisional draft (which only verifies draft ownership), then propagates the del
nvd
CVE-2025-68437P3MEDIUMCVSS 6.8v>= 4.5.0-RC1, < 4.16.19v>= 5.0.0-RC1, < 5.8.232026-01-05
CVE-2025-68437 [MEDIUM] CWE-918 CVE-2025-68437: Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0 Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save__Asset` mutation is vulnerable to Server-Side Request Forgery (SSRF). This vulnerability arises because the `_file` input, specifically its `url` parameter, allows the server to fetch content from arbi
ghsanvdosv
CVE-2026-25492P3MEDIUMCVSS 6.5v>= 5.0.0-RC1, < 5.8.22v>= 3.5.0, < 4.16.182026-02-09
CVE-2026-25492 [MEDIUM] CWE-918 CVE-2026-25492: Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 thro Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save_images_Asset GraphQL mutation can be abused to fetch internal URLs by providing a domain name that resolves to an internal IP address, bypassing hostname validation. When a non-image file extension such as .txt is allowed, downstr
nvd
CVE-2026-25494P3MEDIUMCVSS 6.5v>= 5.0.0-RC1, < 5.8.222026-02-09
CVE-2026-25494 [MEDIUM] CWE-918 CVE-2026-25494: Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 a Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation uses filter_var(..., FILTER_VALIDATE_IP) to block a specific list of IP addresses. However, alternative IP notations (hexadecimal, mixed) are not recognized by this function, allowing attackers
ghsanvdosv
CVE-2026-33158P3MEDIUMCVSS 6.5v>= 4.0.0-RC1, < 4.17.8v>= 5.0.0-RC1, < 5.9.142026-03-24
CVE-2026-33158 [MEDIUM] CWE-639 CVE-2026-33158: Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can read private asset content by calling assets/edit-image with an arbitrary assetId that they are not authorized to view. The endpoint returns image bytes (or a prev
ghsanvdosv
CVE-2026-86731P3MEDIUMCVSS 6.5≥ 5.0.0-RC1, < 5.10.122026-09-08
CVE-2026-86731 [MEDIUM] CWE-862 CVE-2026-86731: Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::a Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action). While the action requires the administrateUsers permission, it does not call requireAdmin() when the targeted user is an administrator, unlike the mirror action actionDeactivateUser. As a result, an
nvd
CVE-2026-55792P3MEDIUMCVSS 6.0v>= 4.0.0-RC1, < 4.18.0v>= 5.0.0-RC1, < 5.10.02026-07-02
CVE-2026-55792 [MEDIUM] CWE-200 CVE-2026-55792: Craft CMS is a content management system (CMS). In versions starting from 4.0.0-RC1 and prior to 4.1 Craft CMS is a content management system (CMS). In versions starting from 4.0.0-RC1 and prior to 4.18.0, and 5.0.0-RC1 and above, prior to 5.10.0, the dataUrl() Twig function is included in Craft’s Twig sandbox allowlist, allowing any control panel user granted the utility:system-messages permission to embed a file-reading payload into system email
ghsanvd
CVE-2019-15929P3CRITICAL≥ 0, < 3.1.72022-05-24
CVE-2019-15929 [CRITICAL] CWE-640 Craft CMS possibility of brute force attempts Craft CMS possibility of brute force attempts In Craft CMS before 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
ghsaosv
CVE-2026-50284P3HIGHCVSS 7.1v=>= 5.0.0-RC1, < 5.9.22v>= 4.0.0-RC1, < 4.17.152026-07-01
CVE-2026-50284 [HIGH] CWE-862 CVE-2026-50284: Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.21 and 4.0.0-RC1 t Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.21 and 4.0.0-RC1 through 4.17.14, theAssetsController::actionDeleteFolder() only requires the deleteAssets: permission for the target folder. It never enforces deletePeerAssets:, even though Assets::deleteFoldersByIds() cascades deletion to every descendant folder and ev
ghsanvd
CVE-2026-79991P3HIGHCVSS 7.1≥ 5.0.0-RC1, < 5.10.132026-09-02
CVE-2026-79991 [HIGH] CWE-89 CVE-2026-79991: Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumen Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schema’s allowed sites. The query path (ElementResolverprepareElementQuery) correctly calls prepa
nvd
CVE-2026-84794P3HIGHCVSS 7.1≥ 5.0.0-RC1, < 5.10.112026-09-02
CVE-2026-84794 [HIGH] CWE-862 CVE-2026-84794: Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when f Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users' folders and force deletion of conflicting files, allowing unauthorized asset deletion and replacement.
nvd
CVE-2025-68436P3MEDIUMCVSS 6.5v>= 5.0.0-RC1, < 5.8.21v>= 4.0.0-RC1, < 4.16.172026-01-05
CVE-2025-68436 [MEDIUM] CWE-200 CVE-2025-68436: Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0 Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the
ghsanvdosv
CVE-2026-25493P3MEDIUMCVSS 6.5v>= 5.0.0-RC1, < 5.8.22v>= 4.0.0-RC1, < 4.16.182026-02-09
CVE-2026-25493 [MEDIUM] CWE-918 CVE-2026-25493: Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 an Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation validates the initial URL hostname and resolved IP against a blocklist, but Guzzle follows HTTP redirects by default. An attacker can bypass all SSRF protections by hosting a redirect that poi
ghsanvdosv
Craftcms Cms vulnerabilities | cvebase