craftcms cms
28 known vulnerabilities in craftcms cms, 3 critical, 3 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2025-32432 CVSS 10.0 critical · actively exploited Craft CMS Code Injection Vulnerability
- CVE-2025-23209 CVSS 8.1 high · actively exploited Craft CMS Code Injection Vulnerability
- CVE-2024-56145 CVSS 9.3 critical · actively exploited Craft CMS Code Injection Vulnerability
Latest vulnerabilities
- CVE-2026-92594 CVSS 8.7 high Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of…
- CVE-2026-92593 CVSS 8.7 high Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() ->…
- CVE-2026-92592 CVSS 8.7 high Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the…
- CVE-2026-92591 CVSS 8.2 high Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous…
- CVE-2026-92590 CVSS 5.1 medium Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that…
- CVE-2026-92589 CVSS 5.3 medium Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an…
- CVE-2026-79987 CVSS 8.7 high A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as…
- CVE-2026-86732 CVSS 8.7 high Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated…
- CVE-2026-86731 CVSS 7.1 high Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the…
- CVE-2026-86730 CVSS 8.7 high Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users…
- CVE-2026-79991 CVSS 7.1 high Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing…
- CVE-2026-79990 CVSS 8.7 high Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing…
- CVE-2026-79989 CVSS 8.7 high The vulnerability allows any authenticated user to change their own password without providing the current password or having an active…
- CVE-2026-84802 CVSS 5.3 medium Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that…
- CVE-2026-84801 CVSS 8.7 high Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with…
- CVE-2026-84800 CVSS 7.1 high Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a…
- CVE-2026-84799 CVSS 5.3 medium Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader…
- CVE-2026-84798 CVSS 7.1 high Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in…
- CVE-2026-84797 CVSS 5.3 medium Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows…
- CVE-2026-84796 CVSS 8.7 high Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate…
- CVE-2026-84795 CVSS 9.2 critical Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin…
- CVE-2026-84794 CVSS 7.1 high Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated…
- CVE-2026-84793 CVSS 4.8 medium Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to…
- CVE-2026-84792 CVSS 5.3 medium Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows…
- CVE-2026-79988 CVSS 8.7 high The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated…
- CVE-2025-32432 CVSS 10.0 critical · actively exploited Craft CMS Code Injection Vulnerability
- CVE-2025-23209 CVSS 8.1 high · actively exploited Craft CMS Code Injection Vulnerability
- CVE-2024-56145 CVSS 9.3 critical · actively exploited Craft CMS Code Injection Vulnerability