Craftcms Craft Cms vulnerabilities

93 known vulnerabilities affecting craftcms/craft_cms.

Total CVEs
93
CISA KEV
4
actively exploited
Public exploits
9
Exploited in wild
0
Severity breakdown
CRITICAL9HIGH31MEDIUM49LOW4

Vulnerabilities

Page 5 of 5
CVE-2020-9757CRITICALCVSS 9.8PoCfixed in 3.3.02020-03-04
CVE-2020-9757 [CRITICAL] CWE-74 CVE-2020-9757: The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads t The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.
nvd
CVE-2019-9554MEDIUMCVSS 6.1PoCv3.1.122019-12-31
CVE-2019-9554 [MEDIUM] CWE-79 CVE-2019-9554: In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when a In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.
nvd
CVE-2019-15929CRITICALCVSS 9.8≤ 3.1.72019-10-24
CVE-2019-15929 [CRITICAL] CWE-640 CVE-2019-15929: In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like nor In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
nvd
CVE-2019-17496MEDIUMCVSS 6.1fixed in 3.3.82019-10-11
CVE-2019-17496 [MEDIUM] CWE-79 CVE-2019-17496: Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletio Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
nvd
CVE-2019-14280MEDIUMCVSS 5.3PoC≥ 2.0.2524, < 2.7.10≥ 3.0.0, < 3.2.62019-07-26
CVE-2019-14280 [MEDIUM] CWE-200 CVE-2019-14280: In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
nvd
CVE-2019-12823MEDIUMCVSS 6.1fixed in 3.1.312019-06-18
CVE-2019-12823 [MEDIUM] CWE-79 CVE-2019-12823: Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS. Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
nvd
CVE-2018-20465HIGHCVSS 7.2≤ 3.0.342018-12-25
CVE-2018-20465 [HIGH] CWE-311 CVE-2018-20465: Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information vi Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes a cleartext username and password to be displayed in a URI field.
nvd
CVE-2018-20418MEDIUMCVSS 4.8PoCv3.0.252018-12-24
CVE-2018-20418 [MEDIUM] CWE-79 CVE-2018-20418: index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title fr index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
nvd
CVE-2018-3814HIGHCVSS 8.8v2.6.30002018-01-01
CVE-2018-3814 [HIGH] CWE-434 CVE-2018-3814: Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Uploa Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option, because this allows a .jpg file to have embedded PHP code, and then be renamed to a .php extension.
nvd
CVE-2017-9516MEDIUMCVSS 5.4PoC≤ 2.6.29812017-06-08
CVE-2017-9516 [MEDIUM] CWE-79 CVE-2017-9516: Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
nvd
CVE-2017-8385MEDIUMCVSS 5.3≤ 2.6.29742017-05-01
CVE-2017-8385 [MEDIUM] CWE-640 CVE-2017-8385: Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email messag Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
nvd
CVE-2017-8383MEDIUMCVSS 5.3≤ 2.6.29742017-05-01
CVE-2017-8383 [MEDIUM] CVE-2017-8383: Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
nvd
CVE-2017-8384MEDIUMCVSS 6.1≤ 2.6.29742017-05-01
CVE-2017-8384 [MEDIUM] CVE-2017-8384: Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSeg Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
nvd