VYPR

CMS

by Craftcms

Source repositories

CVEs (125)

  • CVE-2026-84793MedSep 2, 2026
    risk 0.24cvss 4.8epss 0.00

    Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can inject arbitrary JavaScript payloads in the site name that execute when other users view the control panel…

  • CVE-2026-56393MedJun 21, 2026
    risk 0.24cvss 4.8epss 0.00

    Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rendered without sanitization (e.g., via the checkbox.twig template, which used {{…

  • CVE-2026-56383MedJun 21, 2026
    risk 0.24cvss 4.8epss 0.00

    Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the 'Row Heading' column type. The application fails to sanitize input within row heading default values, allowing an attacker with an administrator account (with…

  • CVE-2026-27128MedFeb 24, 2026
    risk 0.24cvss 4.8epss 0.00

    Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a Time-of-Check-Time-of-Use (TOCTOU) race condition exists in Craft CMS’s token validation service for tokens that explicitly set a limited usage. The…

  • CVE-2026-27126MedFeb 24, 2026
    risk 0.24cvss 4.8epss 0.00

    Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a stored Cross-site Scripting (XSS) vulnerability exists in the `editableTable.twig` component when using the `html` column type. The application fails to sanitize the…

  • CVE-2026-25496MedFeb 9, 2026
    risk 0.24cvss 4.8epss 0.00

    Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a stored XSS vulnerability exists in the Number field type settings. The Prefix and Suffix fields are rendered using the |md|raw Twig filter without…

  • CVE-2026-25491MedFeb 9, 2026
    risk 0.24cvss 4.8epss 0.00

    Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored XSS via Entry Type names. The name is not sanitized when displayed in the Entry Types list. This vulnerability is fixed in 5.8.22.

  • CVE-2024-41800MedJul 25, 2024
    risk 0.24cvss 4.8epss 0.00

    Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that the attacker has knowledge of the victim's…

  • CVE-2026-72779MedAug 11, 2026
    risk 0.22cvss 4.5epss 0.00

    Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create() Twig function restricts class instantiation using a 5-entry blocklist that does not include SplFileObject, allowing an authenticated administrator (with…

  • CVE-2026-92589MedSep 16, 2026
    risk 0.21cvss 4.3epss 0.00

    Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) opens another author's entry in read-only…

  • CVE-2026-84802MedSep 2, 2026
    risk 0.21cvss 4.3epss 0.00

    Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit POST requests to the assets/move-info endpoint with arbitrary…

  • CVE-2026-84799MedSep 2, 2026
    risk 0.21cvss 4.3epss 0.00

    Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can query these relations to read usernames, email addresses,…

  • CVE-2026-84792MedSep 2, 2026
    risk 0.21cvss 4.3epss 0.00

    Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers with limited section permissions can relocate or publish…

  • CVE-2026-72785MedAug 11, 2026
    risk 0.21cvss 4.3epss 0.00

    Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can permanently modify that group's category structure — reordering and…

  • CVE-2026-14794MedJul 6, 2026
    risk 0.21cvss 4.3epss 0.00

    A flaw has been found in Craft CMS up to 4.18.0.1. Affected by this vulnerability is the function actionGetNewUsersData of the file src/controllers/ChartsController.php of the component Charts Endpoint. This manipulation of the argument userGroupId causes improper authorization.…

  • CVE-2026-14793MedJul 6, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability was detected in Craft CMS up to 4.18.0.1. Affected is the function actionReorderSets of the file src/controllers/GlobalsController.php of the component reorder-sets Endpoint. The manipulation results in authorization bypass. The attack can be executed remotely.…

  • CVE-2026-56385MedJun 21, 2026
    risk 0.21cvss 4.3epss 0.00

    Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-file endpoint. The action does not enforce per-asset view authorization before returning preview content, allowing an authenticated low-privileged user to…

  • CVE-2026-56384MedJun 21, 2026
    risk 0.21cvss 4.3epss 0.00

    Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a target private asset can call the endpoint with an attacker-controlled assetId and receive preview HTML containing a signed fallback…

  • CVE-2026-33161MedMar 24, 2026
    risk 0.21cvss 4.3epss 0.00

    Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can call assets/image-editor with the ID of a private asset they cannot view and still receive…

  • CVE-2026-32262MedMar 16, 2026
    risk 0.21cvss 4.3epss 0.00

    Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, the AssetsController->replaceFile() method has a targetFilename body parameter that is used unsanitized in a deleteFile() call…

Page 6 of 7