VYPR

Craft CMS

by Craftcms

Source repositories

CVEs (99)

  • CVE-2017-8383MedMay 1, 2017
    risk 0.35cvss 5.3epss 0.01

    Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.

  • CVE-2026-27127MedFeb 24, 2026
    risk 0.34cvss 6.3epss 0.00

    Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation performs DNS resolution separately from the HTTP request. This Time-of-Check-Time-of-Use (TOCTOU)…

  • CVE-2018-20418MedDec 24, 2018
    risk 0.34cvss 4.8epss 0.04

    index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.

  • CVE-2026-31859MedMar 11, 2026
    risk 0.33cvss 6.1epss 0.00

    Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize return URLs before they are stored in the session. However, strip_tags() only removes HTML tags (angle brackets) -- it does not…

  • CVE-2023-31144MedMay 9, 2023
    risk 0.33cvss 6.1epss 0.00

    Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can deliver a cross-site scripting payload. This issue is fixed in version 3.8.4 and 4.4.4.

  • CVE-2023-30177MedApr 25, 2023
    risk 0.33cvss 6.1epss 0.00

    CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name.

  • CVE-2022-28378MedApr 3, 2022
    risk 0.33cvss 6.1epss 0.01

    Craft CMS before 3.7.29 allows XSS.

  • CVE-2021-27902MedJun 30, 2021
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.

  • CVE-2021-32470MedMay 7, 2021
    risk 0.33cvss 6.1epss 0.01

    Craft CMS before 3.6.13 has an XSS vulnerability.

  • CVE-2019-17496MedOct 11, 2019
    risk 0.33cvss 6.1epss 0.01

    Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.

  • CVE-2019-12823MedJun 18, 2019
    risk 0.33cvss 6.1epss 0.01

    Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.

  • CVE-2017-8052MedApr 22, 2017
    risk 0.33cvss 6.1epss 0.01

    Craft CMS before 2.6.2974 allows XSS attacks.

  • CVE-2024-45406MedSep 9, 2024
    risk 0.29cvss 5.5epss 0.00

    Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.

  • CVE-2023-33196MedMay 26, 2023
    risk 0.29cvss 5.5epss 0.01

    Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.

  • CVE-2023-33197MedMay 26, 2023
    risk 0.29cvss 5.5epss 0.01

    Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.

  • CVE-2026-33051MedMar 20, 2026
    risk 0.28cvss 5.4epss 0.00

    Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor renders the creator’s fullName as raw HTML due to the use of Template::raw() combined with Craft::t() string interpolation. A…

  • CVE-2023-36259MedJan 30, 2024
    risk 0.28cvss 5.4epss 0.00

    Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation.

  • CVE-2024-21622MedJan 3, 2024
    risk 0.28cvss 5.4epss 0.01

    Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. This has been fixed in Craft 4.4.16 and Craft 3.9.6.…

  • CVE-2023-2817MedMay 26, 2023
    risk 0.28cvss 5.4epss 0.00

    A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries…

  • CVE-2022-37246MedSep 21, 2022
    risk 0.28cvss 5.4epss 0.00

    Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.

Page 4 of 5