VYPR

Vendor CVEs

Craftcms

All CVEs

190 total · sorted by risk
  • CVE-2026-25494MedFeb 9, 2026
    risk 0.35cvss 6.5epss 0.00

    Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation uses filter_var(..., FILTER_VALIDATE_IP) to block a specific list of IP addresses. However, alternative IP notations…

  • CVE-2026-25493MedFeb 9, 2026
    risk 0.35cvss 6.5epss 0.00

    Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation validates the initial URL hostname and resolved IP against a blocklist, but Guzzle follows HTTP redirects by default. An…

  • CVE-2026-25492MedFeb 9, 2026
    risk 0.35cvss 6.5epss 0.00

    Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save_images_Asset GraphQL mutation can be abused to fetch internal URLs by providing a domain name that resolves to an internal IP address, bypassing hostname…

  • CVE-2025-68436MedJan 5, 2026
    risk 0.35cvss 6.5epss 0.00

    Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users…

  • CVE-2017-8383MedMay 1, 2017
    risk 0.35cvss 5.3epss 0.01

    Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.

  • CVE-2026-84797MedSep 2, 2026
    risk 0.34cvss 6.3epss 0.00

    Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows authenticated users with createEntries permission to delete peer provisional drafts. Attackers can exploit the deleteProvisionalDraft parameter to…

  • CVE-2026-27127MedFeb 24, 2026
    risk 0.34cvss 6.3epss 0.00

    Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation performs DNS resolution separately from the HTTP request. This Time-of-Check-Time-of-Use (TOCTOU)…

  • CVE-2018-20418MedDec 24, 2018
    risk 0.34cvss 4.8epss 0.04

    index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.

  • CVE-2026-72783MedAug 11, 2026
    risk 0.33cvss 6.2epss 0.00

    Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContained function of the Local file system class. The order of operations validates the path before normalization, so normalization…

  • CVE-2026-31859MedMar 11, 2026
    risk 0.33cvss 6.1epss 0.00

    Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize return URLs before they are stored in the session. However, strip_tags() only removes HTML tags (angle brackets) -- it does not…

  • CVE-2023-31144MedMay 9, 2023
    risk 0.33cvss 6.1epss 0.00

    Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can deliver a cross-site scripting payload. This issue is fixed in version 3.8.4 and 4.4.4.

  • CVE-2023-30177MedApr 25, 2023
    risk 0.33cvss 6.1epss 0.00

    CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name.

  • CVE-2021-41750MedJun 12, 2022
    risk 0.33cvss 6.1epss 0.01

    A cross-site scripting (XSS) vulnerability in the SEOmatic plugin 3.4.10 for Craft CMS 3 allows remote attackers to inject arbitrary web script via a GET to /index.php?action=seomatic/file/seo-file-link with url parameter containing the base64 encoded URL of a malicious web page…

  • CVE-2022-28378MedApr 3, 2022
    risk 0.33cvss 6.1epss 0.01

    Craft CMS before 3.7.29 allows XSS.

  • CVE-2021-27902MedJun 30, 2021
    risk 0.33cvss 6.1epss 0.01

    An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.

  • CVE-2021-32470MedMay 7, 2021
    risk 0.33cvss 6.1epss 0.01

    Craft CMS before 3.6.13 has an XSS vulnerability.

  • CVE-2019-17496MedOct 11, 2019
    risk 0.33cvss 6.1epss 0.01

    Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.

  • CVE-2019-12823MedJun 18, 2019
    risk 0.33cvss 6.1epss 0.01

    Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.

  • CVE-2017-8052MedApr 22, 2017
    risk 0.33cvss 6.1epss 0.01

    Craft CMS before 2.6.2974 allows XSS attacks.

  • CVE-2026-50280MedJul 2, 2026
    risk 0.32cvss —epss 0.00

    Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 and above prior to 5.9.21, the EntriesController::actionMoveToSection() endpoint gates the destination section only by viewEntries:$section->uid rather than requiring saveEntries permission (the source entry…

  • CVE-2026-92591MedSep 16, 2026
    risk 0.31cvss 5.9epss 0.00

    Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed production site whenever PHP remains available but the…

  • CVE-2026-55793MedJul 1, 2026
    risk 0.31cvss —epss 0.00

    Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22, an author-level control panel user can store a malicious JavaScript payload in an entry title. When an admin, or any control panel user with saveEntries for the same Structure section, drags…

  • CVE-2026-56381MedJun 21, 2026
    risk 0.31cvss 4.8epss 0.00

    Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where user group names are rendered without proper HTML escaping. Attackers with admin access can inject arbitrary JavaScript via the user group name field that…

  • CVE-2026-41130MedApr 22, 2026
    risk 0.29cvss —epss 0.00

    Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources. When `trustedHosts` is not explicitly…

  • CVE-2026-41129MedApr 22, 2026
    risk 0.29cvss —epss 0.00

    Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema: "Edit assets in the…

  • CVE-2024-45406MedSep 9, 2024
    risk 0.29cvss 5.5epss 0.00

    Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.

  • CVE-2023-33196MedMay 26, 2023
    risk 0.29cvss 5.5epss 0.01

    Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.

  • CVE-2023-33197MedMay 26, 2023
    risk 0.29cvss 5.5epss 0.01

    Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.

  • CVE-2026-92590MedSep 16, 2026
    risk 0.28cvss 5.4epss 0.00

    Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript through editable fields that…

  • CVE-2026-72784MedAug 11, 2026
    risk 0.28cvss 5.4epss 0.00

    Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL saveAsset mutation, which fetches an attacker-supplied URL server-side. The anti-SSRF validation is incomplete: validateIp()…

  • CVE-2026-33051MedMar 20, 2026
    risk 0.28cvss 5.4epss 0.00

    Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor renders the creator’s fullName as raw HTML due to the use of Template::raw() combined with Craft::t() string interpolation. A…

  • CVE-2026-29177MedMar 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Craft Commerce Order details. Malicious JavaScript can be injected via the Shipping Method Name, Order Reference, or Site Name. When…

  • CVE-2026-29175MedMar 10, 2026
    risk 0.28cvss 5.4epss 0.00

    Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Stored XSS vulnerabilities exist in the Commerce Inventory page. The Product Title, Variant Title, and Variant SKU fields are rendered without proper HTML escaping, allowing an attacker to execute arbitrary…

  • CVE-2026-25483MedFeb 3, 2026
    risk 0.28cvss 5.4epss 0.00

    Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability exists in Craft Commerce’s Order Status History Message. The message is rendered using the |md filter, which permits raw HTML,…

  • CVE-2023-36259MedJan 30, 2024
    risk 0.28cvss 5.4epss 0.00

    Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation.

  • CVE-2024-21622MedJan 3, 2024
    risk 0.28cvss 5.4epss 0.01

    Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. This has been fixed in Craft 4.4.16 and Craft 3.9.6.…

  • CVE-2023-2817MedMay 26, 2023
    risk 0.28cvss 5.4epss 0.00

    A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries…

  • CVE-2022-37246MedSep 21, 2022
    risk 0.28cvss 5.4epss 0.01

    Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.

  • CVE-2022-37251MedSep 16, 2022
    risk 0.28cvss 5.4epss 0.00

    Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.

  • CVE-2022-37247MedSep 16, 2022
    risk 0.28cvss 5.4epss 0.01

    Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.

  • CVE-2022-37248MedSep 16, 2022
    risk 0.28cvss 5.4epss 0.01

    Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.

  • CVE-2022-37250MedSep 16, 2022
    risk 0.28cvss 5.4epss 0.01

    Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.

  • CVE-2020-19626MedMar 26, 2021
    risk 0.28cvss 5.4epss 0.01

    Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new.

  • CVE-2017-8385MedMay 1, 2017
    risk 0.28cvss 5.3epss 0.01

    Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.

  • CVE-2026-50283MedJul 1, 2026
    risk 0.27cvss —epss 0.00

    Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 through 4.17.13 contain an authorization issue in the AssetsController::actionReplaceFile that can delete a source asset without source delete permission by supplying both assetId…

  • CVE-2026-41128MedApr 22, 2026
    risk 0.27cvss —epss 0.00

    Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group authorization for…

  • CVE-2026-33160MedMar 24, 2026
    risk 0.27cvss 5.3epss 0.00

    Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, an unauthenticated user can call assets/generate-transform with a private assetId, receive a valid transform URL, and fetch…

  • CVE-2026-29069MedMar 4, 2026
    risk 0.27cvss 5.3epss 0.00

    Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() endpoint is accessible to unauthenticated users and does not require a permission check for pending users. An attacker with no prior access can trigger activation…

  • CVE-2023-33195MedMay 27, 2023
    risk 0.26cvss 5.0epss 0.01

    Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This issue was patched in version 4.4.6.

  • CVE-2026-50282MedJul 2, 2026
    risk 0.25cvss —epss 0.00

    Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 and above, prior to 5.9.21 and versions 4.0.0-RC1 and above prior to 4.17.14 contain an authorization issue where a forced folder move can delete a conflicting destination folder without destination delete…