Craftcms / Craft Cms
97 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-33162 | Craft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section permissions | MEDIUM | 4.9 | Mar 24, 2026 |
| CVE-2026-33161 | Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users | LOW | 1.3 | Mar 24, 2026 |
| CVE-2026-33160 | Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform URL | LOW | 2.7 | Mar 24, 2026 |
| CVE-2026-33159 | Craft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted users | MEDIUM | 6.9 | Mar 24, 2026 |
| CVE-2026-33158 | Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR) | MEDIUM | 4.9 | Mar 24, 2026 |
| CVE-2026-33157 | Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior | HIGH | 8.7 | Mar 24, 2026 |
| CVE-2026-33051 | Craft CMS Vulnerable to Stored XSS in Revision Context Menu | MEDIUM | 5.3 | Mar 20, 2026 |
| CVE-2026-32267 | Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken() | HIGH | 7.7 | Mar 16, 2026 |
| CVE-2026-32264 | Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController | HIGH | 8.6 | Mar 16, 2026 |
| CVE-2026-32263 | Craft CMS vulnerable to behavior injection RCE via EntryTypesController | HIGH | 8.6 | Mar 16, 2026 |
| CVE-2026-32262 | Craft CMS has a Path Traversal Vulnerability in AssetsController | MEDIUM | 5.3 | Mar 16, 2026 |
| CVE-2026-31859 | Craft has Reflective XSS via incomplete return URL sanitization | MEDIUM | 6.9 | Mar 11, 2026 |
| CVE-2026-31858 | CraftCMS's `ElementSearchController` Affected by Blind SQL Injection | HIGH | 8.7 | Mar 11, 2026 |
| CVE-2026-31857 | CraftCMS has an RCE vulnerability via relational conditionals in the control panel | HIGH | 8.1 | Mar 11, 2026 |
| CVE-2026-29113 | Craft has a potential information disclosure vulnerability in preview tokens | LOW | 2.3 | Mar 10, 2026 |
| CVE-2026-29069 | Craft has an unauthenticated activation email trigger with potential user enumeration | HIGH | 7.8 | Mar 4, 2026 |
| CVE-2026-28784 | Craft is affected by potential authenticated Remote Code Execution via Twig SSTI | HIGH | 8.6 | Mar 4, 2026 |
| CVE-2026-28783 | Craft has a Twig Function Blocklist Bypass | CRITICAL | 9.4 | Mar 4, 2026 |
| CVE-2026-28782 | Craft has a Permission Bypass and IDOR in Duplicate Entry Action | MEDIUM | 5.7 | Mar 4, 2026 |
| CVE-2026-28781 | Craft Affected by Entries Authorship Spoofing via Mass Assignment | HIGH | 7.1 | Mar 4, 2026 |
| CVE-2026-28697 | Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates | CRITICAL | 9.4 | Mar 4, 2026 |
| CVE-2026-28696 | Craft affected by IDOR via GraphQL @parseRefs | HIGH | 8.7 | Mar 4, 2026 |
| CVE-2026-28695 | Craft affected by authenticated RCE via Twig SSTI - create() function + Symfony Process gadget | HIGH | 7.5 | Mar 4, 2026 |
| CVE-2026-27129 | Cloud Metadata SSRF Protection Bypass via IPv6 Resolution | MEDIUM | 5.7 | Feb 24, 2026 |
| CVE-2026-27128 | Craft CMS's race condition in Token Service potentially allows for token usage greater than the token limit | MEDIUM | 6.9 | Feb 24, 2026 |
Showing 1 to 25 of 97 CVEs