VYPR

Packagist (Composer) package

craftcms/cms

pkg:composer/craftcms/cms

Vulnerabilities (103)

  • CVE-2026-25496MedFeb 9, 2026
    affected >= 5.0.0-RC1, < 5.8.22fixed 5.8.22

    Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a stored XSS vulnerability exists in the Number field type settings. The Prefix and Suffix fields are rendered using the |md|raw Twig filter without pro

  • CVE-2026-25495HigFeb 9, 2026
    affected >= 5.0.0-RC1, < 5.8.22fixed 5.8.22

    Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/get-elements endpoint is vulnerable to SQL Injection via the criteria[orderBy] parameter (JSON body). The application fails to sanit

  • CVE-2026-25494MedFeb 9, 2026
    affected >= 5.0.0-RC1, < 5.8.22fixed 5.8.22

    Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation uses filter_var(..., FILTER_VALIDATE_IP) to block a specific list of IP addresses. However, alternative IP notations (he

  • CVE-2026-25493MedFeb 9, 2026
    affected >= 5.0.0-RC1, < 5.8.22fixed 5.8.22

    Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation validates the initial URL hostname and resolved IP against a blocklist, but Guzzle follows HTTP redirects by default. An

  • CVE-2026-25491MedFeb 9, 2026
    affected >= 5.0.0-RC1, < 5.8.22fixed 5.8.22

    Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored XSS via Entry Type names. The name is not sanitized when displayed in the Entry Types list. This vulnerability is fixed in 5.8.22.

  • CVE-2025-68456CriJan 5, 2026
    affected >= 5.0.0-RC1, < 5.8.21fixed 5.8.21

    Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations via specific admin actions, potentially leading to resource exhaustion or information disclosure. Us

  • CVE-2025-68455HigJan 5, 2026
    affected >= 5.0.0-RC1, < 5.8.21fixed 5.8.21

    Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior. Note that attackers must have administrator access to the Craft C

  • CVE-2025-68454HigJan 5, 2026
    affected >= 5.0.0-RC1, < 5.8.21fixed 5.8.21

    Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via Twig SSTI. For this to work, users must have administrator access to the Craft Control Panel,

  • CVE-2025-68437MedJan 5, 2026
    affected >= 5.0.0-RC1, < 5.8.21fixed 5.8.21

    Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save__Asset` mutation is vulnerable to Server-Side Request Forgery (SSRF). This vulnerability arises because the `_file` in

  • CVE-2025-68436MedJan 5, 2026
    affected >= 5.0.0-RC1, < 5.8.21fixed 5.8.21

    Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users sho

  • CVE-2025-57811HigAug 25, 2025
    affected >= 4.0.0-RC1, < 4.16.6fixed 4.16.6

    Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig SSTI (Server-Side Template Injection). This is a follow-up to CVE-2024-52293. This vulnerability has b

  • CVE-2025-54417HigAug 9, 2025
    affected >= 4.13.8, < 4.16.3fixed 4.16.3

    Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass CVE-2025-23209: "Craft CMS has a potential RCE with a compromised security key". To exploit this vulnerability, the project must me

  • CVE-2025-35939MedKEVMay 7, 2025
    affected >= 5.0.0-alpha.1, < 5.7.5fixed 5.7.5

    Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file

  • CVE-2025-46731HigMay 5, 2025
    affected >= 4.0.0-RC1, < 4.14.13fixed 4.14.13

    Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enable

  • CVE-2025-32432CriKEVApr 25, 2025
    affected >= 3.0.0-RC1, < 3.9.15fixed 3.9.15

    Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact

  • CVE-2025-23209HigKEVJan 18, 2025
    affected >= 5.0.0-RC1, < 5.5.8fixed 5.5.8

    Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version

  • CVE-2024-56145CriKEVDec 18, 2024
    affected >= 5.0.0-RC1, < 5.5.2fixed 5.5.2

    Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code executio

  • CVE-2024-52292HigNov 13, 2024
    affected >= 5.0.0-alpha.1, < 5.4.9fixed 5.4.9

    Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, reads the file's content, and converts it into a Base64-encoded string. By embeddi

  • CVE-2024-52291HigNov 13, 2024
    affected >= 5.0.0-RC1, < 5.4.6fixed 5.4.6

    Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a double file:// scheme (e.g., file://file:////). This enables the attacker to specify sensitive folders as the file system, leading to p

  • CVE-2024-52293HigNov 13, 2024
    affected >= 4.0.0-RC1, < 4.12.2fixed 4.12.2

    Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could lead to Remote Code Execution on the server via twig SSTI. This is a sequel to CVE-2023-40035. This vulnerability is fixed in 4.12.

Page 3 of 6