Craft Cms

Craftcms · 97 CVEs

CVE-2026-33162
MEDIUM

Craft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section…

Mar 24, 2026

CVE-2026-33161
LOW

Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users

Mar 24, 2026

CVE-2026-33160
LOW

Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform URL

Mar 24, 2026

CVE-2026-33159
MEDIUM

Craft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted…

Mar 24, 2026

CVE-2026-33158
MEDIUM

Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)

Mar 24, 2026

CVE-2026-33157
HIGH

Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior

Mar 24, 2026

CVE-2026-33051
MEDIUM

Craft CMS Vulnerable to Stored XSS in Revision Context Menu

Mar 20, 2026

CVE-2026-32267
HIGH

Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()

Mar 16, 2026

CVE-2026-32264
HIGH

Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController

Mar 16, 2026

CVE-2026-32263
HIGH

Craft CMS vulnerable to behavior injection RCE via EntryTypesController

Mar 16, 2026

CVE-2026-32262
MEDIUM

Craft CMS has a Path Traversal Vulnerability in AssetsController

Mar 16, 2026

CVE-2026-31859
MEDIUM

Craft has Reflective XSS via incomplete return URL sanitization

Mar 11, 2026

CVE-2026-31858
HIGH

CraftCMS's `ElementSearchController` Affected by Blind SQL Injection

Mar 11, 2026

CVE-2026-31857
HIGH

CraftCMS has an RCE vulnerability via relational conditionals in the control panel

Mar 11, 2026

CVE-2026-29113
LOW

Craft has a potential information disclosure vulnerability in preview tokens

Mar 10, 2026

CVE-2026-29069
HIGH

Craft has an unauthenticated activation email trigger with potential user enumeration

Mar 4, 2026

CVE-2026-28784
HIGH

Craft is affected by potential authenticated Remote Code Execution via Twig SSTI

Mar 4, 2026

CVE-2026-28783
CRITICAL

Craft has a Twig Function Blocklist Bypass

Mar 4, 2026

CVE-2026-28782
MEDIUM

Craft has a Permission Bypass and IDOR in Duplicate Entry Action

Mar 4, 2026

CVE-2026-28781
HIGH

Craft Affected by Entries Authorship Spoofing via Mass Assignment

Mar 4, 2026

CVE-2026-28697
CRITICAL

Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates

Mar 4, 2026

CVE-2026-28696
HIGH

Craft affected by IDOR via GraphQL @parseRefs

Mar 4, 2026

CVE-2026-28695
HIGH

Craft affected by authenticated RCE via Twig SSTI - create() function + Symfony Process gadget

Mar 4, 2026

CVE-2026-27129
MEDIUM

Cloud Metadata SSRF Protection Bypass via IPv6 Resolution

Feb 24, 2026

CVE-2026-27128
MEDIUM

Craft CMS's race condition in Token Service potentially allows for token usage greater than the token limit

Feb 24, 2026

Showing 1 to 25 of 97 CVEs