Craftercms
by Craftercms
Source repositories
CVEs (11)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-0502 | Cri | 0.59 | 9.1 | 0.00 | Jan 15, 2025 | Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS, x86, Windows, 64 bit, ARM allows Directory Indexing, Resource Leak Exposure.This issue affects CrafterCMS: from 4.0.0 before 4.0.8, from 4.1.0 before 4.1.6. | ||
| CVE-2025-6384 | Cri | 0.52 | 9.1 | 0.01 | Jun 19, 2025 | Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain… | ||
| CVE-2023-4136 | Hig | 0.48 | 7.4 | 0.01 | Aug 3, 2023 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27. | ||
| CVE-2021-23260 | Med | 0.42 | 6.5 | 0.00 | Dec 2, 2021 | Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site. | ||
| CVE-2021-23263 | Med | 0.38 | 5.9 | 0.02 | Dec 2, 2021 | Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary). | ||
| CVE-2023-26020 | Med | 0.37 | 5.7 | 0.00 | Feb 17, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1.0 through 3.1.26. | ||
| CVE-2026-1770 | Med | 0.29 | — | 0.00 | Feb 2, 2026 | Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass sandbox restrictions and obtain… | ||
| CVE-2021-23261 | Med | 0.29 | 4.5 | 0.01 | Dec 2, 2021 | Authenticated administrators may override the system configuration file and cause a denial of service. | ||
| CVE-2021-23262 | Med | 0.27 | 4.2 | 0.01 | Dec 2, 2021 | Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE. | ||
| CVE-2021-23259 | Med | 0.27 | 4.2 | 0.01 | Dec 2, 2021 | Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attackers to execute arbitrary commands remotely(RCE). | ||
| CVE-2023-33194 | Low | 0.17 | 3.7 | 0.01 | May 26, 2023 | Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue… |
- risk 0.59cvss 9.1epss 0.00
Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS, x86, Windows, 64 bit, ARM allows Directory Indexing, Resource Leak Exposure.This issue affects CrafterCMS: from 4.0.0 before 4.0.8, from 4.1.0 before 4.1.6.
- risk 0.52cvss 9.1epss 0.01
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain…
- risk 0.48cvss 7.4epss 0.01
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.
- risk 0.42cvss 6.5epss 0.00
Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site.
- risk 0.38cvss 5.9epss 0.02
Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary).
- risk 0.37cvss 5.7epss 0.00
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1.0 through 3.1.26.
- risk 0.29cvss —epss 0.00
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass sandbox restrictions and obtain…
- risk 0.29cvss 4.5epss 0.01
Authenticated administrators may override the system configuration file and cause a denial of service.
- risk 0.27cvss 4.2epss 0.01
Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.
- risk 0.27cvss 4.2epss 0.01
Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attackers to execute arbitrary commands remotely(RCE).
- risk 0.17cvss 3.7epss 0.01
Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue…