VYPR

Craft CMS

by Craftcms

Source repositories

CVEs (103)

  • CVE-2026-25492MedFeb 9, 2026
    risk 0.35cvss 6.5epss 0.00

    Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save_images_Asset GraphQL mutation can be abused to fetch internal URLs by providing a domain name that resolves to an internal IP address, bypassing hostname…

  • CVE-2025-68436MedJan 5, 2026
    risk 0.35cvss 6.5epss 0.00

    Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users…

  • CVE-2017-8383MedMay 1, 2017
    risk 0.35cvss 5.3epss 0.01

    Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.

  • CVE-2026-84797MedSep 2, 2026
    risk 0.34cvss 6.3epss 0.00

    Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows authenticated users with createEntries permission to delete peer provisional drafts. Attackers can exploit the deleteProvisionalDraft parameter to…

  • CVE-2026-27127MedFeb 24, 2026
    risk 0.34cvss 6.3epss 0.00

    Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation performs DNS resolution separately from the HTTP request. This Time-of-Check-Time-of-Use (TOCTOU)…

  • CVE-2018-20418MedDec 24, 2018
    risk 0.34cvss 4.8epss 0.04

    index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.

  • CVE-2026-31859MedMar 11, 2026
    risk 0.33cvss 6.1epss 0.00

    Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize return URLs before they are stored in the session. However, strip_tags() only removes HTML tags (angle brackets) -- it does not…

  • CVE-2023-31144MedMay 9, 2023
    risk 0.33cvss 6.1epss 0.00

    Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can deliver a cross-site scripting payload. This issue is fixed in version 3.8.4 and 4.4.4.

  • CVE-2023-30177MedApr 25, 2023
    risk 0.33cvss 6.1epss 0.00

    CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name.

  • CVE-2022-28378MedApr 3, 2022
    risk 0.33cvss 6.1epss 0.01

    Craft CMS before 3.7.29 allows XSS.

  • CVE-2021-27902MedJun 30, 2021
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.

  • CVE-2021-32470MedMay 7, 2021
    risk 0.33cvss 6.1epss 0.01

    Craft CMS before 3.6.13 has an XSS vulnerability.

  • CVE-2019-17496MedOct 11, 2019
    risk 0.33cvss 6.1epss 0.01

    Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.

  • CVE-2019-12823MedJun 18, 2019
    risk 0.33cvss 6.1epss 0.01

    Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.

  • CVE-2017-8052MedApr 22, 2017
    risk 0.33cvss 6.1epss 0.01

    Craft CMS before 2.6.2974 allows XSS attacks.

  • CVE-2024-45406MedSep 9, 2024
    risk 0.29cvss 5.5epss 0.00

    Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.

  • CVE-2023-33196MedMay 26, 2023
    risk 0.29cvss 5.5epss 0.01

    Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.

  • CVE-2023-33197MedMay 26, 2023
    risk 0.29cvss 5.5epss 0.01

    Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.

  • CVE-2026-33051MedMar 20, 2026
    risk 0.28cvss 5.4epss 0.00

    Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor renders the creator’s fullName as raw HTML due to the use of Template::raw() combined with Craft::t() string interpolation. A…

  • CVE-2023-36259MedJan 30, 2024
    risk 0.28cvss 5.4epss 0.00

    Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation.

Page 4 of 6