VYPR

Craftercms

by Craftercms

Source repositories

CVEs (26)

  • CVE-2021-23266MedMay 16, 2022
    risk 0.28cvss 4.3epss 0.01

    An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.

  • CVE-2021-23262MedDec 2, 2021
    risk 0.27cvss 4.2epss 0.01

    Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.

  • CVE-2021-23259MedDec 2, 2021
    risk 0.27cvss 4.2epss 0.01

    Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attackers to execute arbitrary commands remotely(RCE).

  • CVE-2021-23258MedDec 2, 2021
    risk 0.27cvss 4.2epss 0.01

    Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary commands remotely (RCE).

  • CVE-2021-23265LowMay 16, 2022
    risk 0.23cvss 3.5epss 0.01

    A logged-in and authenticated user with a Reviewer Role may lock a content item.

  • CVE-2023-33194LowMay 26, 2023
    risk 0.17cvss 3.7epss 0.01

    Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue…

Page 2 of 2