craftcms/cms
Packagist127 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting craftcms/cmspage 1 of 3
- CVE-2017-8052MEDIUMCVSS 6.1EG 6.1fixed in 2.6.29742017-04-22
vulnerable: 1.0.26.1 ... 2.6.2973 (276 versions)
Craft CMS before 2.6.2974 allows XSS attacks.
- CVE-2017-8383MEDIUMCVSS 5.3EG 5.3fixed in 2.6.29762017-05-01
vulnerable: 1.0.26.1 ... 2.6.2975 (278 versions)
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
- CVE-2017-8384MEDIUMCVSS 6.1EG 6.1fixed in 2.6.29762017-05-01
vulnerable: 1.0.26.1 ... 2.6.2975 (278 versions)
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
- CVE-2017-8385MEDIUMCVSS 5.3EG 5.3fixed in 2.6.29762017-05-01
vulnerable: 1.0.26.1 ... 2.6.2975 (278 versions)
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
- CVE-2017-9516MEDIUMCVSS 5.4EG 5.4fixed in 2.6.29822017-06-08
vulnerable: 1.0.26.1 ... 2.6.2981 (284 versions)
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
- CVE-2018-20418MEDIUMCVSS 4.8EG 4.82018-12-24
vulnerable: 1.0.26.1 ... 3.0.9 (438 versions)
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
- CVE-2018-20465HIGHCVSS 7.2EG 7.22018-12-25
vulnerable: 1.0.26.1 ... 3.0.9 (451 versions)
Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI F…
- CVE-2018-3814HIGHCVSS 8.8EG 8.82018-01-01
vulnerable: 1.0.26.1 ... 2.6.3000 (303 versions)
Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option, because this allows a .jpg file to have embedded PHP code, and then be renamed to a .php …
- CVE-2019-12823MEDIUMCVSS 6.1EG 6.1fixed in 3.1.312019-06-18
vulnerable: 1.0.26.1 ... 3.1.9.1 (507 versions)
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
- CVE-2019-15929CRITICALCVSS 9.8EG 9.8fixed in 3.1.72019-10-24
vulnerable: 1.0.26.1 ... 3.1.6.1 (478 versions)
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
- CVE-2019-17496MEDIUMCVSS 6.1EG 6.1fixed in 3.3.82019-10-11
vulnerable: 1.0.26.1 ... 3.3.7 (558 versions)
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
- CVE-2020-19626MEDIUMCVSS 5.4EG 5.4fixed in 3.1.332021-03-26
vulnerable: 1.0.26.1 ... 3.1.9.1 (510 versions)
Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new.
- CVE-2021-27902MEDIUMCVSS 6.1EG 6.1fixed in 3.6.02021-06-30
vulnerable: 1.0.26.1 ... 3.6.0-beta.2 (676 versions)
An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.
- CVE-2021-27903CRITICALCVSS 9.8EG 9.8fixed in 3.6.72021-06-30
vulnerable: 1.0.26.1 ... 3.6.6 (686 versions)
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administ…
- CVE-2021-32470MEDIUMCVSS 6.1EG 6.1fixed in 3.6.132021-05-07
vulnerable: 1.0.26.1 ... 3.6.9 (695 versions)
Craft CMS before 3.6.13 has an XSS vulnerability.
- CVE-2021-41824HIGHCVSS 8.8EG 8.8fixed in 3.7.142021-09-30
vulnerable: 3.4.0 ... 3.7.9 (135 versions)
Craft CMS before 3.7.14 allows CSV injection.
- CVE-2022-28378MEDIUMCVSS 6.1EG 6.1fixed in 3.7.292022-04-03
vulnerable: 1.0.26.1 ... 3.7.9 (746 versions)
Craft CMS before 3.7.29 allows XSS.
- CVE-2022-29933HIGHCVSS 8.8EG 8.8fixed in 3.7.362022-05-09
vulnerable: 1.0.26.1 ... 3.7.9 (754 versions)
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the passw…
- CVE-2022-37246MEDIUMCVSS 5.4EG 5.4fixed in 4.2.1 or 3.7.51, by version range2022-09-21
vulnerable: 3.7.39 ... 3.7.50 (16 versions)
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
- CVE-2022-37247MEDIUMCVSS 5.4EG 5.4fixed in 4.2.12022-09-16
vulnerable: 4.0.0 ... 4.2.0.2 (24 versions)
Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.
- CVE-2022-37248MEDIUMCVSS 5.4EG 5.4fixed in 4.2.12022-09-16
vulnerable: 4.0.0 ... 4.2.0.2 (24 versions)
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.
- CVE-2022-37250MEDIUMCVSS 5.4EG 5.4fixed in 4.2.12022-09-16
vulnerable: 4.0.0 ... 4.2.0.2 (24 versions)
Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.
- CVE-2022-37251MEDIUMCVSS 5.4EG 5.4fixed in 3.7.55.2 or 4.2.1, by version range2022-09-16
vulnerable: 4.0.0 ... 4.2.0.2 (24 versions)
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.
- CVE-2022-37783HIGHCVSS 7.5EG 7.5fixed in 3.7.332022-12-05
vulnerable: 3.0.0 ... 3.7.9 (350 versions)
All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called C…
- CVE-2023-23927MEDIUMCVSS 6.1EG 6.1fixed in 4.3.7 or 3.7.64, by version range2023-03-03
vulnerable: 3.7.24 ... 3.7.63.1 (53 versions)
Craft is a platform for creating digital experiences. When you insert a payload inside a label name or instruction of an entry type, an cross-site scripting (XSS) happens in the quick post widget on the admin dashboard. This issue has been…
- CVE-2023-2817MEDIUMCVSS 5.4EG 5.4fixed in 4.4.122023-05-26
vulnerable: 4.0.0 ... 4.4.9 (74 versions)
A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when…
- CVE-2023-30130HIGHCVSS 8.8EG 8.82023-05-12
vulnerable: 1.0.26.1 ... 3.8.1 (807 versions)
An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.
- CVE-2023-30177MEDIUMCVSS 6.1EG 6.1fixed in 3.7.682023-04-25
vulnerable: 1.0.26.1 ... 3.7.9 (798 versions)
CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name.
- CVE-2023-31144MEDIUMCVSS 6.1EG 6.1fixed in 3.8.4 or 4.4.4, by version range2023-05-09
vulnerable: 4.0.0 ... 4.4.3 (60 versions)
Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can deliver a cross-site scripting payload. This issue is fixed in version 3.8.4 and 4.4.4.
- CVE-2023-32679HIGHCVSS 7.2EG 7.2fixed in 4.4.62023-05-19
vulnerable: 4.0.0 ... 4.4.5 (62 versions)
Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension may lead to Remote Code Execution. If the name parameter value is not empty string('') in the View.php's doesTemplateEx…
- CVE-2023-33194LOWCVSS 3.7EG 3.7fixed in 4.4.6 or 3.8.6, by version range2023-05-26
vulnerable: 3.0.0 ... 3.8.5 (410 versions)
Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn��…
- CVE-2023-33195MEDIUMCVSS 5.0EG 5.0fixed in 4.4.62023-05-27
vulnerable: 4.3.0 ... 4.4.5 (30 versions)
Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This issue was patched in version 4.4.6.
- CVE-2023-33196MEDIUMCVSS 5.5EG 5.5fixed in 4.4.72023-05-26
vulnerable: 4.0.0 ... 4.4.6.1 (67 versions)
Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.
- CVE-2023-33197MEDIUMCVSS 5.5EG 5.5fixed in 4.4.62023-05-26
vulnerable: 4.0.0 ... 4.4.5 (65 versions)
Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.
- CVE-2023-33495MEDIUMCVSS 6.1EG 6.12023-06-20
vulnerable: 1.0.26.1 ... 4.4.9 (914 versions)
Craft CMS through 4.4.9 is vulnerable to HTML Injection.
- CVE-2023-36260HIGHCVSS 7.5EG 7.5fixed in 4.6.22024-01-30
vulnerable: 1.0.26.1 ... 4.6.1 (947 versions)
An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings to Feed-Me Name and Feed-Me URL fields, due to saving a feed using an Asset element type w…
- CVE-2023-40035HIGHCVSS 7.2EG 7.2fixed in 4.4.15 or 3.8.15, by version range2023-08-23
vulnerable: 3.0.0 ... 3.8.9 (421 versions)
Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code execution. This vulnerability can lead to malicious control of vulnerable systems and data …
- CVE-2023-41892CRITICALCVSS 9.8EG 9.8fixed in 4.4.152023-09-13
vulnerable: 4.0.0 ... 4.4.9 (77 versions)
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This is…
- CVE-2024-21622HIGHCVSS 8.8EG 8.8fixed in 4.5.11 or 3.9.6, by version range2024-01-03
vulnerable: 3.0.0 ... 3.9.5 (430 versions)
Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. This has bee…
- CVE-2024-37843CRITICALCVSS 9.8EG 9.82024-06-25
vulnerable: 1.0.26.1 ... 3.7.9 (750 versions)
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
- CVE-2024-41800MEDIUMCVSS 4.8EG 4.8fixed in 5.2.32024-07-25
vulnerable: 5.0.0 ... 5.2.2 (39 versions)
Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that th…
- CVE-2024-45406MEDIUMCVSS 5.5EG 5.5fixed in 5.1.22024-09-09
vulnerable: 5.0.0 ... 5.1.1 (9 versions)
Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.
- CVE-2024-52291HIGHCVSS 8.4EG 8.4fixed in 5.4.6 or 4.12.5, by version range2024-11-13
vulnerable: 4.0.0 ... 4.9.7 (155 versions)
Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a double file:// scheme (e.g., file://file:////). This enables the attacker to specify sensitive…
- CVE-2024-52292HIGHCVSS 7.7EG 7.7fixed in 5.4.9 or 4.12.8, by version range2024-11-13
vulnerable: 3.5.13 ... 4.9.7 (346 versions)
Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, reads the file's content, and converts it…
- CVE-2024-52293HIGHCVSS 7.2EG 7.2fixed in 4.12.2 or 5.4.3, by version range2024-11-13
vulnerable: 5.0.0 ... 5.4.2 (53 versions)
Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could lead to Remote Code Execution on the server via twig SSTI. This is a sequel to CVE-2023-40…
- CVE-2024-56145CRITICALCVSS 9.8EG 9.8⚠ KEVfixed in 5.5.2, 4.13.2 or 3.9.14, by version range2024-12-18
vulnerable: 3.0.0 ... 3.9.6 (435 versions)
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these …
- CVE-2025-23209CRITICALCVSS 8.0EG 9.0⚠ KEVfixed in 5.5.8 or 4.13.8, by version range2025-01-18
vulnerable: 4.0.0 ... 4.9.7 (170 versions)
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been comprom…
- CVE-2025-32432CRITICALCVSS 10.0EG 10.0⚠ KEVfixed in 3.9.15, 4.14.15 or 5.6.17, by version range2025-04-25
vulnerable: 5.0.0 ... 5.6.9.1 (101 versions)
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to rem…
- CVE-2025-35939CRITICALCVSS 5.3EG 9.0⚠ KEVfixed in 5.7.5 or 4.15.3, by version range2025-05-07
vulnerable: 1.0.26.1 ... 4.9.7 (1043 versions)
Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to th…
- CVE-2025-46731HIGHCVSS 7.2EG 7.2fixed in 4.14.13 or 5.6.15, by version range2025-05-05
vulnerable: 5.0.0 ... 5.6.9.1 (99 versions)
Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access…
Check whether craftcms/cms is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for craftcms/cms CVEs against the assets you own.
Book a Demo →