Craftcms Cms vulnerabilities
148 known vulnerabilities affecting craftcms/cms.
Total CVEs
148
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL11HIGH54MEDIUM83
Vulnerabilities
Page 8 of 8
CVE-2017-8385P4MEDIUM≥ 0, < 2.6.29762022-05-17
CVE-2017-8385 [MEDIUM] CWE-640 Craft CMS subject to URL forgery
Craft CMS subject to URL forgery
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
ghsaosv
CVE-2022-37251P4MEDIUM≥ 3.7.0-beta.1, < 3.7.55.2≥ 4.0.0-RC1, < 4.2.12022-09-17
CVE-2022-37251 [MEDIUM] CWE-79 Craft CMS vulnerable to Cross-site Scripting via entry revisions and drafts
Craft CMS vulnerable to Cross-site Scripting via entry revisions and drafts
Craft CMS `3.70-RC1`–`3.7.55.1` and `4.0.0-RC1`–`4.2.0.1` are vulnerable to Cross Site Scripting (XSS) via entry revisions and drafts. Versions `3.7.55.2` and `4.2.1` contain patches for this issue.
ghsaosv
CVE-2024-45406P4MEDIUMCVSS 4.8v>= 5.0.0, < 5.1.22024-09-09
CVE-2024-45406 [MEDIUM] CWE-79 CVE-2024-45406: Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrum
Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.
ghsanvdosv
CVE-2023-33194P4MEDIUMCVSS 4.8v>= 4.0.0-RC1, < 4.4.6v>= 3.0.0, <= 3.8.52023-05-26
CVE-2023-33194 [MEDIUM] CWE-80 CVE-2023-33194: Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input
Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was patched in version 4.4.6.
ghsanvdosv
CVE-2021-41824HIGH≥ 3.4.0, < 3.7.142021-10-18
CVE-2021-41824 [HIGH] CWE-1236 CSV Injection Vulnerability
CSV Injection Vulnerability
### Impact
In some circumstances, it was possible to export data in CSV format that could trigger a payload in old versions of Excel.
If you are accepting user input from untrusted sources and will be exporting that data in CSV format from element index pages and there is a chance users will open that on old versions of Excel, then you should update.
### Patches
This has been patched in Craft 3.7.14.
### R
ghsaosv
CVE-2017-8052MEDIUM≥ 0, < 2.6.29742022-05-17
CVE-2017-8052 [MEDIUM] CWE-79 Craft CMS XSS Vulnerability
Craft CMS XSS Vulnerability
Craft CMS before 2.6.2974 allows XSS attacks.
ghsaosv
CVE-2021-32470MEDIUM≥ 0, < 3.6.132022-03-18
CVE-2021-32470 [MEDIUM] CWE-79 Craft CMS Cross-site Scripting Vulnerability
Craft CMS Cross-site Scripting Vulnerability
Craft CMS before 3.6.13 has an XSS vulnerability.
ghsaosv
CVE-2022-28378MEDIUM≥ 0, < 3.7.292022-04-04
CVE-2022-28378 [MEDIUM] CWE-79 Cross-site Scripting in craftcms/cms
Cross-site Scripting in craftcms/cms
Craft CMS before 3.7.29 allows cross-site scripting.
ghsaosv
← Previous8 / 8