Craftercms
by Craftercms
Source repositories
CVEs (26)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-23266 | Med | 0.28 | 4.3 | 0.01 | May 16, 2022 | An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator. | ||
| CVE-2021-23262 | Med | 0.27 | 4.2 | 0.01 | Dec 2, 2021 | Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE. | ||
| CVE-2021-23259 | Med | 0.27 | 4.2 | 0.01 | Dec 2, 2021 | Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attackers to execute arbitrary commands remotely(RCE). | ||
| CVE-2021-23258 | Med | 0.27 | 4.2 | 0.01 | Dec 2, 2021 | Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary commands remotely (RCE). | ||
| CVE-2021-23265 | Low | 0.23 | 3.5 | 0.01 | May 16, 2022 | A logged-in and authenticated user with a Reviewer Role may lock a content item. | ||
| CVE-2023-33194 | Low | 0.17 | 3.7 | 0.01 | May 26, 2023 | Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue… |
- risk 0.28cvss 4.3epss 0.01
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
- risk 0.27cvss 4.2epss 0.01
Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.
- risk 0.27cvss 4.2epss 0.01
Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have security restrictions, which will cause attackers to execute arbitrary commands remotely(RCE).
- risk 0.27cvss 4.2epss 0.01
Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have security restrictions, which will cause attackers to execute arbitrary commands remotely (RCE).
- risk 0.23cvss 3.5epss 0.01
A logged-in and authenticated user with a Reviewer Role may lock a content item.
- risk 0.17cvss 3.7epss 0.01
Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This issue…
Page 2 of 2