cbcvebase.

Craftcms Cms vulnerabilities

148 known vulnerabilities affecting craftcms/cms.

Total CVEs
148
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL11HIGH54MEDIUM83

Vulnerabilities

Page 7 of 8
CVE-2026-28782P4MEDIUMCVSS 4.3v>= 5.0.0-RC1, < 5.9.0-beta.1v>= 4.0.0-RC1, < 4.17.0-beta.12026-03-04
CVE-2026-28782 [MEDIUM] CWE-639 CVE-2026-28782: Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, the "Duplicate" Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, the "Duplicate" entry action does not properly verify if the user has permission to perform this action on the specific target elements. Even with only "View Entries" permission (where the "Duplicate" action is restricted in the UI), a user can bypass this restricti
ghsanvdosv
CVE-2026-72785P4MEDIUMCVSS 4.3≥ 5.0.0-RC1, < 5.10.62026-08-11
CVE-2026-72785 [MEDIUM] CWE-863 CVE-2026-72785: Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-pane Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can permanently modify that group's category structure — reordering and re-parenting categories — via the structures/move-element action. The structureEdit
nvd
CVE-2026-29113P4MEDIUMCVSS 4.3v>= 4.0.0-RC1, < 4.17.3v>= 5.0.0-RC1, < 5.9.72026-03-10
CVE-2026-29113 [MEDIUM] CWE-352 CVE-2026-29113: Craft is a content management system (CMS). Prior to 4.17.3 and 5.9.7, Craft CMS has a CSRF issue in Craft is a content management system (CMS). Prior to 4.17.3 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action does not require POST and does not enforce a CSRF token, an attacker can force a logged-in victim editor to mint a
ghsanvdosv
CVE-2026-84799P4MEDIUMCVSS 4.3≥ 5.0.0-RC1, < 5.11.02026-09-02
CVE-2026-84799 [MEDIUM] CWE-285 CVE-2026-84799: Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations i Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can query these relations to read usernames, email addresses, and full names of any content author or uploader including administrators
nvd
CVE-2017-8384P4MEDIUMCVSS 6.1≥ 0, < 2.6.29762022-05-17
CVE-2017-8384 [MEDIUM] CWE-79 Craft CMS XSS Vulnerability Craft CMS XSS Vulnerability Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
ghsaosv
CVE-2023-33196P4MEDIUMCVSS 5.4v>= 4.0.0-RC1, <= 4.4.62023-05-26
CVE-2023-33196 [MEDIUM] CWE-80 CVE-2023-33196: Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.
ghsanvdosv
CVE-2017-8383P4MEDIUM≥ 0, < 2.6.29762022-05-13
CVE-2017-8383 [MEDIUM] CWE-284 Craft CMS Unauthorized View Craft CMS Unauthorized View Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the `craft/app/` folder.
ghsaosv
CVE-2021-27902P4MEDIUM≥ 0, < 3.6.02021-07-02
CVE-2021-27902 [MEDIUM] CWE-79 Craft CMS Cross-site Scripting Vulnerability Craft CMS Cross-site Scripting Vulnerability An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.
ghsaosv
CVE-2019-12823P4MEDIUM≥ 0, < 3.1.312022-05-24
CVE-2019-12823 [MEDIUM] CWE-79 Craft CMS XSS Vulnerability Craft CMS XSS Vulnerability Craft CMS before 3.1.31 does not properly filter XML feeds, thus allowing XSS.
ghsaosv
CVE-2019-17496P4MEDIUM≥ 0, < 3.3.82022-05-24
CVE-2019-17496 [MEDIUM] CWE-79 Craft CMS XSS Vulnerability Craft CMS XSS Vulnerability Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
ghsaosv
CVE-2026-25491P4MEDIUMCVSS 4.8v>= 5.0.0-RC1, < 5.8.222026-02-09
CVE-2026-25491 [MEDIUM] CWE-79 CVE-2026-25491: Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored X Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored XSS via Entry Type names. The name is not sanitized when displayed in the Entry Types list. This vulnerability is fixed in 5.8.22.
ghsanvdosv
CVE-2026-33161P4MEDIUMCVSS 4.3v>= 4.0.0-RC1, < 4.17.8v>= 5.0.0-RC1, < 5.9.142026-03-24
CVE-2026-33161 [MEDIUM] CWE-200 CVE-2026-33161: Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can call assets/image-editor with the ID of a private asset they cannot view and still receive editor response data, including focalPoint. The endpoint returns private
ghsanvdosv
CVE-2022-37246P4MEDIUM≥ 4.0.0-RC1, < 4.2.1≥ 3.7.39, < 3.7.512022-09-22
CVE-2022-37246 [MEDIUM] CWE-79 Craft CMS Cross-site Scripting vulnerability Craft CMS Cross-site Scripting vulnerability Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line `label: elementInfo.label`.
ghsaosv
CVE-2020-19626P4MEDIUM≥ 0, < 3.1.332022-05-24
CVE-2020-19626 [MEDIUM] CWE-79 Craft CMS Cross-site Scripting Vulnerability Craft CMS Cross-site Scripting Vulnerability Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via `/admin/settings/sites/new`.
ghsaosv
CVE-2022-37250P4MEDIUM≥ 4.0.0-RC1, < 4.2.12022-09-17
CVE-2022-37250 [MEDIUM] CWE-79 Craft CMS Stored Cross-site Scripting in User Addresses Title Craft CMS Stored Cross-site Scripting in User Addresses Title Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in `/admin/myaccount`.
ghsaosv
CVE-2022-37248P4MEDIUM≥ 4.0.0-RC1, < 4.2.12022-09-17
CVE-2022-37248 [MEDIUM] CWE-79 Craft CMS Cross site Scripting vulnerability Craft CMS Cross site Scripting vulnerability Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via `src/helpers/Cp.php`.
ghsaosv
CVE-2022-37247P4MEDIUM≥ 4.0.0-RC1, < 4.2.12022-09-17
CVE-2022-37247 [MEDIUM] CWE-79 Craft CMS vulnerable to stored Cross-site Scripting via /admin/settings/fields page Craft CMS vulnerable to stored Cross-site Scripting via /admin/settings/fields page Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.
ghsaosv
CVE-2023-30177P4MEDIUM≥ 0, < 3.7.682023-04-25
CVE-2023-30177 [MEDIUM] CWE-79 Cross Site Scripting in CraftCMS Cross Site Scripting in CraftCMS CraftCMS prior to version 3.7.68 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name.
ghsaosv
CVE-2026-56381P4MEDIUMCVSS 4.8≥ 5.0.0-RC1, < 5.8.222026-06-21
CVE-2026-56381 [MEDIUM] CWE-79 CVE-2026-56381: Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Pe Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where user group names are rendered without proper HTML escaping. Attackers with admin access can inject arbitrary JavaScript via the user group name field that executes when other users view or edit permissions.
nvd
CVE-2026-84793P4MEDIUMCVSS 4.8≥ 5.0.0-RC1, < 5.10.112026-09-02
CVE-2026-84793 [MEDIUM] CWE-79 CVE-2026-84793: Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can inject arbitrary JavaScript payloads in the site name that execute when other users view the control panel settings pages.
nvd
Craftcms Cms vulnerabilities | cvebase