cbcvebase.

Craftcms Cms vulnerabilities

148 known vulnerabilities affecting craftcms/cms.

Total CVEs
148
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL11HIGH54MEDIUM83

Vulnerabilities

Page 5 of 8
CVE-2026-28781P3MEDIUMCVSS 6.5v>= 5.0.0-RC1, < 5.9.0-beta.1v>= 4.0.0-RC1, < 4.17.0-beta.12026-03-04
CVE-2026-28781 [MEDIUM] CWE-639 CVE-2026-28781: Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creat Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the authorId attribute. A user with "Create Entries" permission can inject the authorIds[] (or authorId) parameter into the POST request, which the backend processes without verifying if the current user is au
ghsanvdosv
CVE-2026-33159P3MEDIUMCVSS 6.5v>= 4.0.0-RC1, < 4.17.8v>= 5.0.0-RC1, < 5.9.142026-03-24
CVE-2026-33159 [MEDIUM] CWE-306 CVE-2026-33159: Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, guest users can access Config Sync updater index, obtain signed data, and execute state-changing Config Sync actions (regenerate-yaml, apply-yaml-changes) without authentication. This issue has been patc
ghsanvdosv
CVE-2026-33162P3MEDIUMCVSS 6.5v>= 5.3.0, < 5.9.142026-03-24
CVE-2026-33162 [MEDIUM] CWE-285 CVE-2026-33162: Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an auth Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/entries/move-to-section, even when they do not have saveEntries:{sectionUid} permission for either source or destination section. This issue has been pa
ghsanvdosv
CVE-2026-50280P3MEDIUMCVSS 6.0v>= 5.0.0-RC1, < 5.9.212026-07-02
CVE-2026-50280 [MEDIUM] CWE-284 CVE-2026-50280: Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 and above prior to 5.9.21, the Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 and above prior to 5.9.21, the EntriesController::actionMoveToSection() endpoint gates the destination section only by viewEntries:$section->uid rather than requiring saveEntries permission (the source entry is separately checked via Entry::canMove()). As a result, a low-privilege
ghsanvd
CVE-2022-37783P3HIGH≥ 3.0.0, < 3.7.332022-12-05
CVE-2022-37783 [HIGH] CWE-200 Craft CMS discloses password hashes Craft CMS discloses password hashes All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site Request Forgery attacks. The CRAFT_CSRF_TOKEN cookie discloses the password hash in without encoding it whereas the corres
ghsaosv
CVE-2026-44012P3HIGHCVSS 7.1v>= 5.0.0-RC1, < 5.9.182026-05-12
CVE-2026-44012 [HIGH] CWE-862 CVE-2026-44012: Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::a Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() fetches an asset by ID and returns its filename and complete folder hierarchy (including volume handle, volume UID, folder names, folder UIDs, and folder URI paths) without checking whether the requesting user has viewAssets or viewP
ghsanvd
CVE-2026-72780P3MEDIUMCVSS 6.5≥ 5.0.0-RC1, < 5.10.52026-08-11
CVE-2026-72780 [MEDIUM] CWE-294 CVE-2026-72780: Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion valida Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can replay captured login request bodies containing requestOptions and response to create additional authenticated sessions for victim accounts.
nvd
CVE-2026-41130P3MEDIUMCVSS 5.5v>= 5.0.0-RC1, < 5.9.15v>= 4.0.0-RC1, < 4.17.92026-04-22
CVE-2026-41130 [MEDIUM] CWE-918 CVE-2026-41130: Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources. When `trustedHosts` is not explicitly restricted (default configuration), the application trusts the client-suppl
nvd
CVE-2026-72787P3MEDIUMCVSS 6.4≥ 5.0.0-RC1, < 5.10.82026-08-12
CVE-2026-72787 [MEDIUM] CWE-79 CVE-2026-72787: Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can create element drafts can inject malicious JavaScript that executes in the browser of any higher-privileged user viewing the affected ele
nvd
CVE-2018-20465P3HIGH≥ 0, ≤ 3.0.342022-05-13
CVE-2018-20465 [HIGH] CWE-1336 Craft CMS Vulnerable to Server-Side Template Injection Craft CMS Vulnerable to Server-Side Template Injection Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a `{%` string for `craft.app.config.DB.user` and `craft.app.config.DB.password` in the URI Format of the Site Settings, which causes a cleartext username and password to be displayed in a URI field.
ghsaosv
CVE-2026-41128P3MEDIUMCVSS 5.3v>= 5.6.0, < 5.9.152026-04-22
CVE-2026-41128 [MEDIUM] CWE-862 CVE-2026-41128: Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePer Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group authorization for additions, it performs no equivalent authorization check for removals, s
nvd
CVE-2026-50283P3MEDIUMCVSS 5.3v>= 5.0.0-RC1, < 5.9.21v>= 4.0.0-RC1, < 4.17.142026-07-01
CVE-2026-50283 [MEDIUM] CWE-639 CVE-2026-50283: Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 thr Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 through 4.17.13 contain an authorization issue in the AssetsController::actionReplaceFile that can delete a source asset without source delete permission by supplying both assetId and sourceAssetId. AssetsController::actionReplaceFile() supports replacin
ghsanvd
CVE-2023-36260P3HIGH≥ 0, < 4.6.22024-01-30
CVE-2023-36260 [HIGH] CWE-74 Craft CMS Feed-Me Craft CMS Feed-Me An issue discovered in Craft CMS version 4.6.1.1 allows remote attackers to cause a denial of service (DoS) via crafted string to Feed-Me Name and Feed-Me URL fields due to saving a feed using an Asset element type with no volume selected.
ghsaosv
CVE-2026-55793P3MEDIUMCVSS 5.9v>= 5.0.0-RC1, < 5.9.232026-07-01
CVE-2026-55793 [MEDIUM] CWE-79 CVE-2026-55793: Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22, an author-leve Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22, an author-level control panel user can store a malicious JavaScript payload in an entry title. When an admin, or any control panel user with saveEntries for the same Structure section, drags another entry under the poisoned entry in table view, the payload executes
ghsanvd
CVE-2026-41129P4MEDIUMCVSS 5.5v>= 5.0.0-RC1, < 5.9.15v>= 4.0.0-RC1, < 4.17.92026-04-22
CVE-2026-41129 [MEDIUM] CWE-918 CVE-2026-41129: Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5. Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema: "Edit assets in the volume" and "Create assets in the volume." Versions 4.17.9 and 5.9.15 patc
nvd
CVE-2026-72784P4MEDIUMCVSS 5.4≥ 5.0.0-RC1, < 5.10.6≥ 4.0.0-RC1, < 4.18.22026-08-11
CVE-2026-72784 [MEDIUM] CWE-918 CVE-2026-72784: Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side r Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL saveAsset mutation, which fetches an attacker-supplied URL server-side. The anti-SSRF validation is incomplete: validateIp() does not cover CGNAT (100.64.0.0/10) or NAT64 (64:ff9b::/96) ranges, and the only
nvd
CVE-2026-33160P4MEDIUMCVSS 5.3v>= 4.0.0-RC1, < 4.17.8v>= 5.0.0-RC1, < 5.9.142026-03-24
CVE-2026-33160 [MEDIUM] CWE-639 CVE-2026-33160: Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, an unauthenticated user can call assets/generate-transform with a private assetId, receive a valid transform URL, and fetch transformed image bytes. The endpoint is anonymous and does not enforce per-ass
ghsanvdosv
CVE-2026-29069P4MEDIUMCVSS 5.3v>= 5.0.0-RC1, < 5.9.0-beta.2v>= 4.0.0-RC1, < 4.17.0-beta.22026-03-04
CVE-2026-29069 [MEDIUM] CWE-639 CVE-2026-29069: Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendA Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() endpoint is accessible to unauthenticated users and does not require a permission check for pending users. An attacker with no prior access can trigger activation emails for any pending user account by knowing or guessing the user ID.
ghsanvdosv
CVE-2026-72783P4MEDIUMCVSS 6.2≥ 5.0.0-RC1, < 5.10.6≥ 4.0.0-RC1, < 4.18.22026-08-11
CVE-2026-72783 [MEDIUM] CWE-22 CVE-2026-72783: Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical p Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContained function of the Local file system class. The order of operations validates the path before normalization, so normalization could invalidate prior validation assumptions (a desanitization-style issue)
nvd
CVE-2026-50282P4MEDIUMCVSS 4.9v>= 5.0.0-RC1, < 5.9.21v>= 4.0.0-RC1, <= 4.17.142026-07-02
CVE-2026-50282 [MEDIUM] CWE-862 CVE-2026-50282: Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and ve Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above prior to 4.17.14 contain an authorization issue where a forced folder move can delete a conflicting destination folder without destination delete permission. Function craft\\controllers\\AssetsController::actionMoveFolder()
ghsanvd
Craftcms Cms vulnerabilities | cvebase