Packagist (Composer) package
craftcms/cms
pkg:composer/craftcms/cms
Vulnerabilities (103)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2017-8384 | Med | 6.1 | < 2.6.2976 | 2.6.2976 | May 1, 2017 | Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052. | |
| CVE-2017-8383 | Med | 5.3 | < 2.6.2976 | 2.6.2976 | May 1, 2017 | Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder. | |
| CVE-2017-8052 | Med | 6.1 | < 2.6.2974 | 2.6.2974 | Apr 22, 2017 | Craft CMS before 2.6.2974 allows XSS attacks. |
- affected < 2.6.2976fixed 2.6.2976
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
- affected < 2.6.2976fixed 2.6.2976
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
- affected < 2.6.2974fixed 2.6.2974
Craft CMS before 2.6.2974 allows XSS attacks.
Page 6 of 6