Craft Cms
Craftcms · 97 CVEs
Craft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section…
Mar 24, 2026
Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users
Mar 24, 2026
Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform URL
Mar 24, 2026
Craft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted…
Mar 24, 2026
Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)
Mar 24, 2026
Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior
Mar 24, 2026
Craft CMS Vulnerable to Stored XSS in Revision Context Menu
Mar 20, 2026
Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()
Mar 16, 2026
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
Mar 16, 2026
Craft CMS vulnerable to behavior injection RCE via EntryTypesController
Mar 16, 2026
Craft CMS has a Path Traversal Vulnerability in AssetsController
Mar 16, 2026
Craft has Reflective XSS via incomplete return URL sanitization
Mar 11, 2026
CraftCMS's `ElementSearchController` Affected by Blind SQL Injection
Mar 11, 2026
CraftCMS has an RCE vulnerability via relational conditionals in the control panel
Mar 11, 2026
Craft has a potential information disclosure vulnerability in preview tokens
Mar 10, 2026
Craft has an unauthenticated activation email trigger with potential user enumeration
Mar 4, 2026
Craft is affected by potential authenticated Remote Code Execution via Twig SSTI
Mar 4, 2026
Craft has a Twig Function Blocklist Bypass
Mar 4, 2026
Craft has a Permission Bypass and IDOR in Duplicate Entry Action
Mar 4, 2026
Craft Affected by Entries Authorship Spoofing via Mass Assignment
Mar 4, 2026
Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates
Mar 4, 2026
Craft affected by IDOR via GraphQL @parseRefs
Mar 4, 2026
Craft affected by authenticated RCE via Twig SSTI - create() function + Symfony Process gadget
Mar 4, 2026
Cloud Metadata SSRF Protection Bypass via IPv6 Resolution
Feb 24, 2026
Craft CMS's race condition in Token Service potentially allows for token usage greater than the token limit
Feb 24, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-33162 | Craft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section permissions | MEDIUM | 0.38% | Mar 24, 2026 |
| CVE-2026-33161 | Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users | LOW | 0.34% | Mar 24, 2026 |
| CVE-2026-33160 | Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform URL | LOW | 0.41% | Mar 24, 2026 |
| CVE-2026-33159 | Craft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted users | MEDIUM | 0.43% | Mar 24, 2026 |
| CVE-2026-33158 | Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR) | MEDIUM | 0.42% | Mar 24, 2026 |
| CVE-2026-33157 | Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior | HIGH | 1.06% | Mar 24, 2026 |
| CVE-2026-33051 | Craft CMS Vulnerable to Stored XSS in Revision Context Menu | MEDIUM | 0.29% | Mar 20, 2026 |
| CVE-2026-32267 | Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken() | HIGH | 0.49% | Mar 16, 2026 |
| CVE-2026-32264 | Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController | HIGH | 0.68% | Mar 16, 2026 |
| CVE-2026-32263 | Craft CMS vulnerable to behavior injection RCE via EntryTypesController | HIGH | 0.65% | Mar 16, 2026 |
| CVE-2026-32262 | Craft CMS has a Path Traversal Vulnerability in AssetsController | MEDIUM | 0.35% | Mar 16, 2026 |
| CVE-2026-31859 | Craft has Reflective XSS via incomplete return URL sanitization | MEDIUM | 0.25% | Mar 11, 2026 |
| CVE-2026-31858 | CraftCMS's `ElementSearchController` Affected by Blind SQL Injection | HIGH | 0.47% | Mar 11, 2026 |
| CVE-2026-31857 | CraftCMS has an RCE vulnerability via relational conditionals in the control panel | HIGH | 0.89% | Mar 11, 2026 |
| CVE-2026-29113 | Craft has a potential information disclosure vulnerability in preview tokens | LOW | 0.18% | Mar 10, 2026 |
| CVE-2026-29069 | Craft has an unauthenticated activation email trigger with potential user enumeration | HIGH | 0.35% | Mar 4, 2026 |
| CVE-2026-28784 | Craft is affected by potential authenticated Remote Code Execution via Twig SSTI | HIGH | 0.65% | Mar 4, 2026 |
| CVE-2026-28783 | Craft has a Twig Function Blocklist Bypass | CRITICAL | 0.57% | Mar 4, 2026 |
| CVE-2026-28782 | Craft has a Permission Bypass and IDOR in Duplicate Entry Action | MEDIUM | 0.30% | Mar 4, 2026 |
| CVE-2026-28781 | Craft Affected by Entries Authorship Spoofing via Mass Assignment | HIGH | 0.47% | Mar 4, 2026 |
| CVE-2026-28697 | Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates | CRITICAL | 1.14% | Mar 4, 2026 |
| CVE-2026-28696 | Craft affected by IDOR via GraphQL @parseRefs | HIGH | 0.44% | Mar 4, 2026 |
| CVE-2026-28695 | Craft affected by authenticated RCE via Twig SSTI - create() function + Symfony Process gadget | HIGH | 0.63% | Mar 4, 2026 |
| CVE-2026-27129 | Cloud Metadata SSRF Protection Bypass via IPv6 Resolution | MEDIUM | 0.42% | Feb 24, 2026 |
| CVE-2026-27128 | Craft CMS's race condition in Token Service potentially allows for token usage greater than the token limit | MEDIUM | 0.21% | Feb 24, 2026 |
Showing 1 to 25 of 97 CVEs