cbcvebase.

Craftcms Cms vulnerabilities

148 known vulnerabilities affecting craftcms/cms.

Total CVEs
148
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL11HIGH54MEDIUM83

Vulnerabilities

Page 6 of 8
CVE-2026-32262P4MEDIUMCVSS 4.3v>= 4.0.0-RC1, < 4.17.5v>= 5.0.0-RC1, < 5.9.112026-03-16
CVE-2026-32262 [MEDIUM] CWE-22 CVE-2026-32262: Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, the AssetsController->replaceFile() method has a targetFilename body parameter that is used unsanitized in a deleteFile() call before Assets::prepareAssetName() is applied on save. This allows an authenti
ghsanvdosv
CVE-2026-33051P4MEDIUMCVSS 5.4v>= 5.9.0-beta.1, < 5.9.112026-03-20
CVE-2026-33051 [MEDIUM] CWE-79 CVE-2026-33051: Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revisio Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor renders the creator’s fullName as raw HTML due to the use of Template::raw() combined with Craft::t() string interpolation. A low-privileged control panel user (e.g., Author) can set their fullName to an XSS p
ghsanvdosv
CVE-2026-72779P4MEDIUMCVSS 4.5≥ 5.0.0-RC1, < 5.10.6≥ 4.0.0-RC1, < 4.18.22026-08-11
CVE-2026-72779 [MEDIUM] CWE-184 CVE-2026-72779: Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnera Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create() Twig function restricts class instantiation using a 5-entry blocklist that does not include SplFileObject, allowing an authenticated administrator (with allowAdminChanges=true) to configure a malicious entry type title or URI form
nvd
CVE-2026-31859P4MEDIUMCVSS 6.9≥ 4.15.3, < 4.17.3≥ 5.7.5, < 5.9.72026-03-11
CVE-2026-31859 [MEDIUM] CWE-116 CraftCMS vulnerable to reflective XSS via incomplete return URL sanitization CraftCMS vulnerable to reflective XSS via incomplete return URL sanitization ### Summary The fix for CVE-2025-35939 in `craftcms/cms` introduced a `strip_tags()` call in `src/web/User.php` to sanitize return URLs before they are stored in the session. However, `strip_tags()` only removes HTML tags (angle brackets) -- it does not inspect or filter URL schemes. Payloads like `javascript:a
ghsaosv
CVE-2026-84802P4MEDIUMCVSS 4.3≥ 5.7.0, < 5.10.122026-09-02
CVE-2026-84802 [MEDIUM] CWE-862 CVE-2026-84802: Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in Asse Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit POST requests to the assets/move-info endpoint with arbitrary folderIds to retrieve asset count and total storage size for volumes they
nvd
CVE-2026-27128P4MEDIUMCVSS 4.8v>= 4.5.0-RC1, < 4.16.19v>= 5.0.0-RC1, < 5.8.232026-02-24
CVE-2026-27128 [MEDIUM] CWE-367 CVE-2026-27128: Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 thro Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a Time-of-Check-Time-of-Use (TOCTOU) race condition exists in Craft CMS’s token validation service for tokens that explicitly set a limited usage. The `getTokenRoute()` method reads a token’s usage count, checks if it’s within limits, then
ghsanvdosv
CVE-2026-84792P4MEDIUMCVSS 4.3≥ 5.0.0-RC1, < 5.10.112026-09-02
CVE-2026-84792 [MEDIUM] CWE-862 CVE-2026-84792: Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-index Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish entries to unauthorized sections by overwriting the sectionId attribute after
nvd
CVE-2023-33195P4MEDIUMCVSS 6.1v>= 4.3.0, <= 4.4.52023-05-27
CVE-2023-33195 [MEDIUM] CWE-79 CVE-2023-33195: Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This issue was patched in version 4.4.6.
ghsanvdosv
CVE-2023-33495P4MEDIUM≥ 0, ≤ 4.4.92023-06-20
CVE-2023-33495 [MEDIUM] CWE-79 Craft CMS vulnerable to HTML injection Craft CMS vulnerable to HTML injection Craft CMS through 4.4.9 is vulnerable to HTML Injection.
ghsaosv
CVE-2026-25496P4MEDIUMCVSS 4.8v>= 5.0.0-RC1, < 5.8.22v>= 4.0.0-RC1, < 4.16.182026-02-09
CVE-2026-25496 [MEDIUM] CWE-79 CVE-2026-25496: Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 an Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a stored XSS vulnerability exists in the Number field type settings. The Prefix and Suffix fields are rendered using the |md|raw Twig filter without proper escaping, allowing script execution when the Number field is display
ghsanvdosv
CVE-2026-56383P4MEDIUMCVSS 4.8≥ 4.5.0-beta.1, < 4.16.19≥ 5.0.0-RC1, < 5.8.232026-06-21
CVE-2026-56383 [MEDIUM] CWE-79 CVE-2026-56383: Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig compo Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the 'Row Heading' column type. The application fails to sanitize input within row heading default values, allowing an attacker with an administrator account (with allowAdminChanges enabled) to inject arbitrary JavaScript that executes w
nvd
CVE-2026-56385P4MEDIUMCVSS 4.3≥ 5.0.0-RC1, < 5.9.14≥ 4.0.0-RC1, < 4.17.82026-06-21
CVE-2026-56385 [MEDIUM] CWE-639 CVE-2026-56385: Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypa Craft CMS versions >= 5.0.0-RC1, = 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-file endpoint. The action does not enforce per-asset view authorization before returning preview content, allowing an authenticated low-privileged user to supply a controlled assetId for an asset they are not permitted to view and still rece
nvd
CVE-2026-56384P4MEDIUMCVSS 4.3≥ 4.0.0-RC1, < 4.17.8≥ 5.0.0-RC1, < 5.9.142026-06-21
CVE-2026-56384 [MEDIUM] CWE-862 CVE-2026-56384: Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Con Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a target private asset can call the endpoint with an attacker-controlled assetId and receive preview HTML containing a signed fallback transform preview link for that private asset, because no asset-view perm
nvd
CVE-2023-31144P4MEDIUMCVSS 6.1v>= 3.0.0, < 3.8.4v>= 4.0.0, < 4.4.42023-05-09
CVE-2023-31144 [MEDIUM] CWE-79 CVE-2023-31144: Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can deliver a cross-site scripting payload. This issue is fixed in version 3.8.4 and 4.4.4.
ghsanvdosv
CVE-2023-23927P4MEDIUMCVSS 5.4fixed in 4.3.72023-03-03
CVE-2023-23927 [MEDIUM] CWE-79 CVE-2023-23927: Craft is a platform for creating digital experiences. When you insert a payload inside a label name Craft is a platform for creating digital experiences. When you insert a payload inside a label name or instruction of an entry type, an cross-site scripting (XSS) happens in the quick post widget on the admin dashboard. This issue has been fixed in version 4.3.7.
ghsanvdosv
CVE-2023-33197P4MEDIUMCVSS 5.4v>= 4.0.0-RC1, <= 4.4.52023-05-26
CVE-2023-33197 [MEDIUM] CWE-80 CVE-2023-33197: Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.
ghsanvdosv
CVE-2023-2817P4MEDIUM≥ 4.0.0-RC1, < 4.4.122023-05-26
CVE-2023-2817 [MEDIUM] CWE-79 Stored cross site scripting in Craft CMS Stored cross site scripting in Craft CMS A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively. This issue was patched in version 4.4.12.
ghsaosv
CVE-2026-14793P4MEDIUM≥ 4.0.0-RC1, < 4.18.1≥ 5.0.0-RC1, < 5.10.32026-08-06
CVE-2026-14793 [MEDIUM] CWE-862 Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets The `reorder-sets` action in Craft CMS’s `GlobalsController` is missing the `requireAdmin()` check that the adjacent `save-set` and `delete-set` actions both enforce. Any authenticated control panel user can POST to `/actions/globals/reorder-sets` and permanently reord
ghsa
CVE-2026-56393P4MEDIUMCVSS 4.8≥ 5.0.0-RC1, < 5.9.0-beta.1≥ 4.0.0-RC1, < 4.17.0-beta.12026-06-21
CVE-2026-56393 [MEDIUM] CWE-79 CVE-2026-56393: Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multipl Craft CMS 4.x (>= 4.0.0-RC1, = 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rendered without sanitization (e.g., via the checkbox.twig template, which used {{ label|raw }}). An authenticated administrator (with allowAdminChanges enabled) can inject malicious p
nvd
CVE-2026-27126P4MEDIUMCVSS 4.8v>= 4.5.0-RC1, < 4.16.19v>= 5.0.0-RC1, < 5.8.232026-02-24
CVE-2026-27126 [MEDIUM] CWE-79 CVE-2026-27126: Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 thro Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a stored Cross-site Scripting (XSS) vulnerability exists in the `editableTable.twig` component when using the `html` column type. The application fails to sanitize the input, allowing an attacker to execute arbitrary JavaScript when another
ghsanvdosv
Craftcms Cms vulnerabilities | cvebase