craftcms/cms
Packagist127 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting craftcms/cmspage 2 of 3
- CVE-2025-54417HIGHCVSS 8.8EG 8.8fixed in 4.16.3 or 5.8.4, by version range2025-08-09
vulnerable: 5.5.10 ... 5.8.3 (48 versions)
Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass CVE-2025-23209: "Craft CMS has a potential RCE with a compromised security key". To exploi…
- CVE-2025-57811HIGHCVSS 7.2EG 7.2fixed in 4.16.6 or 5.8.7, by version range2025-08-25
vulnerable: 5.0.0 ... 5.8.6 (126 versions)
Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig SSTI (Server-Side Template Injection). This is a follow-up to…
- CVE-2025-68436MEDIUMCVSS 6.5EG 6.5fixed in 5.8.21 or 4.16.17, by version range2026-01-05
vulnerable: 4.0.0 ... 4.9.7 (226 versions)
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo vi…
- CVE-2025-68437MEDIUMCVSS 6.8EG 6.8fixed in 5.8.21 or 4.16.17, by version range2026-01-05
vulnerable: 3.5.0 ... 4.9.7 (429 versions)
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save_<VolumeName>_Asset` mutation is vulnerable to Server-Side Request Forgery (SSRF). This vu…
- CVE-2025-68454HIGHCVSS 8.8EG 8.8fixed in 5.8.21 or 4.16.17, by version range2026-01-05
vulnerable: 4.0.0 ... 4.9.7 (226 versions)
Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via Twig SSTI. For this to work, users must have administ…
- CVE-2025-68455HIGHCVSS 7.2EG 7.2fixed in 5.8.21 or 4.16.17, by version range2026-01-05
vulnerable: 4.0.0 ... 4.9.7 (226 versions)
Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior. Note that attackers must…
- CVE-2025-68456CRITICALCVSS 9.1EG 9.1fixed in 5.8.21 or 4.16.17, by version range2026-01-05
vulnerable: 3.0.0 ... 4.9.7 (668 versions)
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations via specific admin actions, potentially leading to resource…
- CVE-2026-14793MEDIUMCVSS 4.3EG 4.3fixed in 4.18.1 or 5.10.3, by version range2026-07-06
vulnerable: 5.0.0 ... 5.9.9 (174 versions)
A vulnerability was detected in Craft CMS up to 4.18.0.1. Affected is the function actionReorderSets of the file src/controllers/GlobalsController.php of the component reorder-sets Endpoint. The manipulation results in authorization bypass…
- CVE-2026-14794MEDIUMCVSS 4.3EG 4.3fixed in 4.18.1 or 5.10.3, by version range2026-07-06
vulnerable: 5.0.0 ... 5.9.9 (174 versions)
A flaw has been found in Craft CMS up to 4.18.0.1. Affected by this vulnerability is the function actionGetNewUsersData of the file src/controllers/ChartsController.php of the component Charts Endpoint. This manipulation of the argument us…
- CVE-2026-25491MEDIUMCVSS 4.8EG 4.8fixed in 5.8.222026-02-09
vulnerable: 5.0.0 ... 5.8.9 (143 versions)
Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored XSS via Entry Type names. The name is not sanitized when displayed in the Entry Types list. This vulnerability is fixed in 5.8.22.
- CVE-2026-25493MEDIUMCVSS 6.5EG 6.5fixed in 5.8.22 or 4.16.18, by version range2026-02-09
vulnerable: 4.0.0 ... 4.9.7 (227 versions)
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation validates the initial URL hostname and resolved IP against a blocklist, but Guzz…
- CVE-2026-25494MEDIUMCVSS 6.5EG 6.5fixed in 5.8.22 or 4.16.18, by version range2026-02-09
vulnerable: 4.0.0 ... 4.9.7 (227 versions)
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation uses filter_var(..., FILTER_VALIDATE_IP) to block a specific list of IP address…
- CVE-2026-25495HIGHCVSS 8.8EG 8.8fixed in 5.8.22 or 4.16.18, by version range2026-02-09
vulnerable: 4.0.0 ... 4.9.7 (227 versions)
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/get-elements endpoint is vulnerable to SQL Injection via the criteria[orderBy] parameter (J…
- CVE-2026-25496MEDIUMCVSS 4.8EG 4.8fixed in 5.8.22 or 4.16.18, by version range2026-02-09
vulnerable: 4.0.0 ... 4.9.7 (227 versions)
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a stored XSS vulnerability exists in the Number field type settings. The Prefix and Suffix fields are rendered …
- CVE-2026-25497HIGHCVSS 8.8EG 8.8fixed in 5.9.0-beta.1 or 4.17.0-beta.1, by version range2026-02-09
vulnerable: 4.0.0 ... 4.9.7 (229 versions)
Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege Escalation vulnerability in Craft CMS’s GraphQL API that allows an authenticated user w…
- CVE-2026-25498HIGHCVSS 7.2EG 7.2fixed in 5.8.22 or 4.16.18, by version range2026-02-09
vulnerable: 4.0.0 ... 4.9.7 (227 versions)
Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a Remote Code Execution (RCE) vulnerability exists in Craft CMS where the assembleLayoutFromPost() function in src/se…
- CVE-2026-27126MEDIUMCVSS 4.8EG 4.8fixed in 4.16.19 or 5.8.23, by version range2026-02-24
vulnerable: 5.0.0 ... 5.8.9 (144 versions)
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a stored Cross-site Scripting (XSS) vulnerability exists in the `editableTable.twig` component when using the `html` column typ…
- CVE-2026-27127MEDIUMCVSS 6.3EG 6.3fixed in 5.8.23 or 4.16.19, by version range2026-02-24
vulnerable: 3.5.0 ... 4.9.7 (431 versions)
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation performs DNS resolution separately from the HTTP request. This Time…
- CVE-2026-27128MEDIUMCVSS 4.8EG 4.8fixed in 4.16.19 or 5.8.23, by version range2026-02-24
vulnerable: 5.0.0 ... 5.8.9 (144 versions)
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a Time-of-Check-Time-of-Use (TOCTOU) race condition exists in Craft CMS’s token validation service for tokens that explicitly…
- CVE-2026-27129MEDIUMCVSS 6.5EG 6.5fixed in 5.8.23 or 4.16.19, by version range2026-02-24
vulnerable: 3.5.0 ... 4.9.7 (431 versions)
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation uses `gethostbyname()`, which only resolves IPv4 addresses. When a …
- CVE-2026-28695HIGHCVSS 7.2EG 7.2fixed in 5.9.0-beta.1 or 4.17.0-beta.1, by version range2026-03-04
vulnerable: 4.0.0 ... 4.9.7 (229 versions)
Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Template Injection using the create() Twig function combined with a Symfony Process gadget chain. The create() Twig functio…
- CVE-2026-28696HIGHCVSS 7.5EG 7.5fixed in 4.17.0-beta.1 or 5.9.0-beta.1, by version range2026-03-04
vulnerable: 5.0.0 ... 5.8.9 (145 versions)
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal reference tags (e.g., {user:1:email}), can be abused by both authenticated users and unauthen…
- CVE-2026-28697CRITICALCVSS 9.1EG 9.1fixed in 5.9.0-beta.1 or 4.17.0-beta.1, by version range2026-03-04
vulnerable: 4.0.0 ... 4.9.7 (229 versions)
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fie…
- CVE-2026-28781MEDIUMCVSS 6.5EG 6.5fixed in 5.9.0-beta.1 or 4.17.0-beta.1, by version range2026-03-04
vulnerable: 4.0.0 ... 4.9.7 (229 versions)
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the authorId attribute. A user with "Create Entries" permission can inject the authorIds[] (or au…
- CVE-2026-28782MEDIUMCVSS 4.3EG 4.3fixed in 5.9.0-beta.1 or 4.17.0-beta.1, by version range2026-03-04
vulnerable: 4.0.0 ... 4.9.7 (229 versions)
Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, the "Duplicate" entry action does not properly verify if the user has permission to perform this action on the specific target elements. Even with only "V…
- CVE-2026-28783CRITICALCVSS 9.1EG 9.1fixed in 5.9.0-beta.1 or 4.17.0-beta.1, by version range2026-03-04
vulnerable: 4.0.0 ... 4.9.7 (229 versions)
Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerous PHP functions from being called via Twig non-Closure arrow functions. In order to be abl…
- CVE-2026-28784HIGHCVSS 7.2EG 7.2fixed in 5.9.0-beta.1 or 4.17.0-beta.1, by version range2026-03-04
vulnerable: 4.0.0 ... 4.9.7 (229 versions)
Craft is a content management system (CMS). Prior to 5.8.22 and 4.16.18, it is possible to craft a malicious payload using the Twig map filter in text fields that accept Twig input under Settings in the Craft control panel or using the Sys…
- CVE-2026-29069MEDIUMCVSS 5.3EG 5.3fixed in 5.9.0-beta.2 or 4.17.0-beta.2, by version range2026-03-04
vulnerable: 4.0.0 ... 4.9.7 (230 versions)
Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() endpoint is accessible to unauthenticated users and does not require a permission check for pending users. An attacker wit…
- CVE-2026-29113MEDIUMCVSS 4.3EG 4.3fixed in 4.17.3 or 5.9.7, by version range2026-03-10
vulnerable: 5.0.0 ... 5.9.6 (154 versions)
Craft is a content management system (CMS). Prior to 4.17.3 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action do…
- CVE-2026-31857HIGHCVSS 8.8EG 8.8fixed in 5.9.9 or 4.17.4, by version range2026-03-11
vulnerable: 4.0.0 ... 4.9.7 (239 versions)
Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The BaseElementSelectConditionRule::getElementIds() method passes user-controlled str…
- CVE-2026-31858HIGHCVSS 8.8EG 8.8fixed in 5.9.92026-03-11
vulnerable: 5.0.0 ... 5.9.8 (156 versions)
Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() protection that was added to ElementIndexesController in CVE-2026-25495. The exact same SQL injection vulnerability (in…
- CVE-2026-31859MEDIUMCVSS 6.1EG 6.1fixed in 4.17.3 or 5.9.7, by version range2026-03-11
vulnerable: 5.7.10 ... 5.9.6 (44 versions)
Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize return URLs before they are stored in the session. However, strip_tags() only removes HTM…
- CVE-2026-32262MEDIUMCVSS 4.3EG 4.3fixed in 4.17.5 or 5.9.11, by version range2026-03-16
vulnerable: 5.0.0 ... 5.9.9 (158 versions)
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, the AssetsController->replaceFile() method has a targetFilename body parameter that is use…
- CVE-2026-32263HIGHCVSS 7.2EG 7.2fixed in 5.9.112026-03-16
vulnerable: 5.6.0 ... 5.9.9 (80 versions)
Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTypesController.php, the $settings array from parse_str is passed directly to Craft::configure() without Component::cleans…
- CVE-2026-32264HIGHCVSS 7.2EG 7.2fixed in 4.17.5 or 5.9.11, by version range2026-03-16
vulnerable: 5.0.0 ... 5.9.9 (158 versions)
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, there is a Behavior injection RCE vulnerability in ElementIndexesController and FieldsCont…
- CVE-2026-32267CRITICALCVSS 9.8EG 9.8fixed in 4.17.6 or 5.9.12, by version range2026-03-16
vulnerable: 5.0.0 ... 5.9.9 (159 versions)
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escal…
- CVE-2026-33051MEDIUMCVSS 5.4EG 5.4fixed in 5.9.112026-03-20
vulnerable: 5.9.0 ... 5.9.9 (13 versions)
Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor renders the creator’s fullName as raw HTML due to the use of Template::raw() combined with Cra…
- CVE-2026-33157HIGHCVSS 7.2EG 7.2fixed in 5.9.132026-03-24
vulnerable: 5.6.0 ... 5.9.9 (82 versions)
Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.13, a Remote Code Execution (RCE) vulnerability exists in Craft CMS, it can be exploited by any authenticated user with control panel access. This is …
- CVE-2026-33158MEDIUMCVSS 6.5EG 6.5fixed in 4.17.8 or 5.9.14, by version range2026-03-24
vulnerable: 5.0.0 ... 5.9.9 (161 versions)
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can read private asset content by calling assets/edit-…
- CVE-2026-33159MEDIUMCVSS 6.5EG 6.5fixed in 5.9.14 or 4.17.8, by version range2026-03-24
vulnerable: 4.0.0 ... 4.9.7 (239 versions)
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, guest users can access Config Sync updater index, obtain signed data, and execute state-ch…
- CVE-2026-33160MEDIUMCVSS 5.3EG 5.3fixed in 5.9.14 or 4.17.8, by version range2026-03-24
vulnerable: 4.0.0 ... 4.9.7 (239 versions)
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, an unauthenticated user can call assets/generate-transform with a private assetId, receive…
- CVE-2026-33161MEDIUMCVSS 4.3EG 4.3fixed in 5.9.14 or 4.17.8, by version range2026-03-24
vulnerable: 4.0.0 ... 4.9.7 (239 versions)
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can call assets/image-editor with the ID of a private …
- CVE-2026-33162MEDIUMCVSS 6.5EG 6.5fixed in 5.9.142026-03-24
vulnerable: 5.3.0 ... 5.9.9 (122 versions)
Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/entries/move-to-section, even when they …
- CVE-2026-41128MEDIUMCVSS 5.3EG 5.3fixed in 5.9.152026-04-22
vulnerable: 5.6.0 ... 5.9.9 (84 versions)
Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups(…
- CVE-2026-41129MEDIUMCVSS 5.5EG 5.5fixed in 5.9.15 or 4.17.9, by version range2026-04-22
vulnerable: 4.0.0 ... 4.9.7 (240 versions)
Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the use…
- CVE-2026-41130MEDIUMCVSS 5.5EG 5.5fixed in 5.9.15 or 4.17.9, by version range2026-04-22
vulnerable: 4.0.0 ... 4.9.7 (240 versions)
Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources. …
- CVE-2026-44010HIGHCVSS 7.1EG 7.1fixed in 5.9.18 or 4.17.12, by version range2026-05-12
vulnerable: 4.0.0 ... 4.9.7 (240 versions)
Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element resolver (src/gql/resolvers/elements/Address.php) performs no schema scope filtering on top-level queries. A GraphQL API t…
- CVE-2026-44011HIGHCVSS 8.6EG 8.6fixed in 4.17.12 or 5.9.18, by version range2026-05-12
vulnerable: 5.0.0 ... 5.9.9 (164 versions)
Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an input-handling flaw in a Yii object creation path that let any authenticated user inject malicious configuration and execu…
- CVE-2026-44012HIGHCVSS 7.1EG 7.1fixed in 5.9.182026-05-12
vulnerable: 5.0.0 ... 5.9.9 (165 versions)
Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() fetches an asset by ID and returns its filename and complete folder hierarchy (including volume handle, volume UID, fol…
- CVE-2026-50279HIGHCVSS 7.6EG 7.6fixed in 5.9.212026-07-02
vulnerable: 5.0.0 ... 5.9.9 (168 versions)
Craft CMS is a content management system (CMS). IN versions 5.0.0-RC1 and above prior to 5.9.21, theEntriesController::actionSaveEntry() performs entry-edit permission checks before request-controlled author changes are applied to the mode…
Check whether craftcms/cms is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for craftcms/cms CVEs against the assets you own.
Book a Demo →