VYPR

Craftercms

by Craftercms

Source repositories

CVEs (11)

  • CVE-2025-0502CriJan 15, 2025
    risk 0.59cvss 9.1epss 0.00

    Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS, x86, Windows, 64 bit, ARM allows Directory Indexing, Resource Leak Exposure.This issue affects CrafterCMS: from 4.0.0 before 4.0.8, from 4.1.0 before 4.1.6.

  • CVE-2025-6384CriJun 19, 2025
    risk 0.52cvss 9.1epss 0.01

    Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass Sandbox restrictions and obtain…

  • CVE-2023-4136HigAug 3, 2023
    risk 0.48cvss 7.4epss 0.01

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected XSS.This issue affects CrafterCMS: from 4.0.0 through 4.0.2, from 3.1.0 through 3.1.27.

  • CVE-2021-23260MedDec 2, 2021
    risk 0.42cvss 6.5epss 0.00

    Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site.

  • CVE-2021-23263MedDec 2, 2021
    risk 0.38cvss 5.9epss 0.02

    Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary).

  • CVE-2023-26020MedFeb 17, 2023
    risk 0.37cvss 5.7epss 0.00

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, ARM, 64 bit allows SQL Injection.This issue affects CrafterCMS v4.0 from 4.0.0 through 4.0.1, and v3.1 from 3.1.0 through 3.1.26.

  • CVE-2026-1770MedFeb 2, 2026
    risk 0.29cvss epss 0.00

    Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypass. By inserting malicious Groovy elements, an attacker may bypass sandbox restrictions and obtain…

  • CVE-2021-23261MedDec 2, 2021
    risk 0.29cvss 4.5epss 0.01

    Authenticated administrators may override the system configuration file and cause a denial of service.

  • CVE-2021-23262MedDec 2, 2021
    risk 0.27cvss 4.2epss 0.01

    Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.

  • CVE-2021-23259MedDec 2, 2021
    risk 0.27cvss 4.2epss 0.01

    Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attackers to execute arbitrary commands remotely(RCE).

  • CVE-2023-33194LowMay 26, 2023
    risk 0.17cvss 3.7epss 0.01

    Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue…