cbcvebase.

Craftcms Cms vulnerabilities

148 known vulnerabilities affecting craftcms/cms.

Total CVEs
148
CISA KEV
4
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL11HIGH54MEDIUM83

Vulnerabilities

Page 8 of 8
CVE-2017-8385P4MEDIUM≥ 0, < 2.6.29762022-05-17
CVE-2017-8385 [MEDIUM] CWE-640 Craft CMS subject to URL forgery Craft CMS subject to URL forgery Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
ghsaosv
CVE-2022-37251P4MEDIUM≥ 3.7.0-beta.1, < 3.7.55.2≥ 4.0.0-RC1, < 4.2.12022-09-17
CVE-2022-37251 [MEDIUM] CWE-79 Craft CMS vulnerable to Cross-site Scripting via entry revisions and drafts Craft CMS vulnerable to Cross-site Scripting via entry revisions and drafts Craft CMS `3.70-RC1`–`3.7.55.1` and `4.0.0-RC1`–`4.2.0.1` are vulnerable to Cross Site Scripting (XSS) via entry revisions and drafts. Versions `3.7.55.2` and `4.2.1` contain patches for this issue.
ghsaosv
CVE-2024-45406P4MEDIUMCVSS 4.8v>= 5.0.0, < 5.1.22024-09-09
CVE-2024-45406 [MEDIUM] CWE-79 CVE-2024-45406: Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrum Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.
ghsanvdosv
CVE-2023-33194P4MEDIUMCVSS 4.8v>= 4.0.0-RC1, < 4.4.6v>= 3.0.0, <= 3.8.52023-05-26
CVE-2023-33194 [MEDIUM] CWE-80 CVE-2023-33194: Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue was patched in version 4.4.6.
ghsanvdosv
CVE-2021-41824HIGH≥ 3.4.0, < 3.7.142021-10-18
CVE-2021-41824 [HIGH] CWE-1236 CSV Injection Vulnerability CSV Injection Vulnerability ### Impact In some circumstances, it was possible to export data in CSV format that could trigger a payload in old versions of Excel. If you are accepting user input from untrusted sources and will be exporting that data in CSV format from element index pages and there is a chance users will open that on old versions of Excel, then you should update. ### Patches This has been patched in Craft 3.7.14. ### R
ghsaosv
CVE-2017-8052MEDIUM≥ 0, < 2.6.29742022-05-17
CVE-2017-8052 [MEDIUM] CWE-79 Craft CMS XSS Vulnerability Craft CMS XSS Vulnerability Craft CMS before 2.6.2974 allows XSS attacks.
ghsaosv
CVE-2021-32470MEDIUM≥ 0, < 3.6.132022-03-18
CVE-2021-32470 [MEDIUM] CWE-79 Craft CMS Cross-site Scripting Vulnerability Craft CMS Cross-site Scripting Vulnerability Craft CMS before 3.6.13 has an XSS vulnerability.
ghsaosv
CVE-2022-28378MEDIUM≥ 0, < 3.7.292022-04-04
CVE-2022-28378 [MEDIUM] CWE-79 Cross-site Scripting in craftcms/cms Cross-site Scripting in craftcms/cms Craft CMS before 3.7.29 allows cross-site scripting.
ghsaosv
Craftcms Cms vulnerabilities | cvebase