VYPR

CMS

by Packagist

CVEs (2)

  • CVE-2026-56382HigJun 21, 2026
    risk 0.47cvss 7.2epss 0.01

    Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in the FieldsController::actionRenderCardPreview() method, which passes the fieldLayoutConfig POST parameter directly to Fields::createLayout() without calling…

  • CVE-2026-56384MedJun 21, 2026
    risk 0.21cvss 4.3epss 0.00

    Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a target private asset can call the endpoint with an attacker-controlled assetId and receive preview HTML containing a signed fallback…