craftcms/cms
Packagist125 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting craftcms/cmspage 2 of 3
- CVE-2025-54417HIGHCVSS 8.8EG 8.8✓ Fixed in 5.8.42025-08-09
vulnerable: 5.5.10 ... 5.8.3 (48 versions)
Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass CVE-2025-23209: "Craft CMS has a potential RCE with a compromised security key". To exploi…
- CVE-2025-57811HIGHCVSS 7.2EG 7.2✓ Fixed in 5.8.72025-08-25
vulnerable: 5.0.0 ... 5.8.6 (126 versions)
Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig SSTI (Server-Side Template Injection). This is a follow-up to…
- CVE-2025-68436MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.16.172026-01-05
vulnerable: 4.0.0 ... 4.9.7 (226 versions)
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo vi…
- CVE-2025-68437MEDIUMCVSS 6.8EG 6.8✓ Fixed in 4.16.172026-01-05
vulnerable: 3.5.0 ... 4.9.7 (429 versions)
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save_<VolumeName>_Asset` mutation is vulnerable to Server-Side Request Forgery (SSRF). This vu…
- CVE-2025-68454HIGHCVSS 8.8EG 8.8✓ Fixed in 4.16.172026-01-05
vulnerable: 4.0.0 ... 4.9.7 (226 versions)
Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via Twig SSTI. For this to work, users must have administ…
- CVE-2025-68455HIGHCVSS 7.2EG 7.2✓ Fixed in 4.16.172026-01-05
vulnerable: 4.0.0 ... 4.9.7 (226 versions)
Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior. Note that attackers must…
- CVE-2025-68456CRITICALCVSS 9.1EG 9.1✓ Fixed in 4.16.172026-01-05
vulnerable: 3.0.0 ... 4.9.7 (668 versions)
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations via specific admin actions, potentially leading to resource…
- CVE-2026-14793MEDIUMCVSS 4.3EG 4.3✓ Fixed in 5.10.32026-07-06
vulnerable: 5.0.0 ... 5.9.9 (174 versions)
A vulnerability was detected in Craft CMS up to 4.18.0.1. Affected is the function actionReorderSets of the file src/controllers/GlobalsController.php of the component reorder-sets Endpoint. The manipulation results in authorization bypass…
- CVE-2026-25491MEDIUMCVSS 4.8EG 4.8✓ Fixed in 5.8.222026-02-09
vulnerable: 5.0.0 ... 5.8.9 (143 versions)
Craft is a platform for creating digital experiences. From 5.0.0-RC1 to 5.8.21, Craft has a stored XSS via Entry Type names. The name is not sanitized when displayed in the Entry Types list. This vulnerability is fixed in 5.8.22.
- CVE-2026-25493MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.16.182026-02-09
vulnerable: 4.0.0 ... 4.9.7 (227 versions)
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation validates the initial URL hostname and resolved IP against a blocklist, but Guzz…
- CVE-2026-25494MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.16.182026-02-09
vulnerable: 4.0.0 ... 4.9.7 (227 versions)
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL mutation uses filter_var(..., FILTER_VALIDATE_IP) to block a specific list of IP address…
- CVE-2026-25495HIGHCVSS 8.8EG 8.8✓ Fixed in 4.16.182026-02-09
vulnerable: 4.0.0 ... 4.9.7 (227 versions)
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/get-elements endpoint is vulnerable to SQL Injection via the criteria[orderBy] parameter (J…
- CVE-2026-25496MEDIUMCVSS 4.8EG 4.8✓ Fixed in 4.16.182026-02-09
vulnerable: 4.0.0 ... 4.9.7 (227 versions)
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a stored XSS vulnerability exists in the Number field type settings. The Prefix and Suffix fields are rendered …
- CVE-2026-25497HIGHCVSS 8.8EG 8.8✓ Fixed in 4.17.0-beta.12026-02-09
vulnerable: 4.0.0 ... 4.9.7 (229 versions)
Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege Escalation vulnerability in Craft CMS’s GraphQL API that allows an authenticated user w…
- CVE-2026-25498HIGHCVSS 7.2EG 7.2✓ Fixed in 4.16.182026-02-09
vulnerable: 4.0.0 ... 4.9.7 (227 versions)
Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a Remote Code Execution (RCE) vulnerability exists in Craft CMS where the assembleLayoutFromPost() function in src/se…
- CVE-2026-27126MEDIUMCVSS 4.8EG 4.8✓ Fixed in 5.8.232026-02-24
vulnerable: 5.0.0 ... 5.8.9 (144 versions)
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a stored Cross-site Scripting (XSS) vulnerability exists in the `editableTable.twig` component when using the `html` column typ…
- CVE-2026-27127MEDIUMCVSS 6.3EG 6.3✓ Fixed in 4.16.192026-02-24
vulnerable: 3.5.0 ... 4.9.7 (431 versions)
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation performs DNS resolution separately from the HTTP request. This Time…
- CVE-2026-27128MEDIUMCVSS 4.8EG 4.8✓ Fixed in 5.8.232026-02-24
vulnerable: 5.0.0 ... 5.8.9 (144 versions)
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a Time-of-Check-Time-of-Use (TOCTOU) race condition exists in Craft CMS’s token validation service for tokens that explicitly…
- CVE-2026-27129MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.16.192026-02-24
vulnerable: 3.5.0 ... 4.9.7 (431 versions)
Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation uses `gethostbyname()`, which only resolves IPv4 addresses. When a …
- CVE-2026-28695HIGHCVSS 7.2EG 7.2✓ Fixed in 4.17.0-beta.12026-03-04
vulnerable: 4.0.0 ... 4.9.7 (229 versions)
Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Template Injection using the create() Twig function combined with a Symfony Process gadget chain. The create() Twig functio…
- CVE-2026-28696HIGHCVSS 7.5EG 7.5✓ Fixed in 5.9.0-beta.12026-03-04
vulnerable: 5.0.0 ... 5.8.9 (145 versions)
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal reference tags (e.g., {user:1:email}), can be abused by both authenticated users and unauthen…
- CVE-2026-28697CRITICALCVSS 9.1EG 9.1✓ Fixed in 4.17.0-beta.12026-03-04
vulnerable: 4.0.0 ... 4.9.7 (229 versions)
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fie…
- CVE-2026-28781MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.17.0-beta.12026-03-04
vulnerable: 4.0.0 ... 4.9.7 (229 versions)
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the authorId attribute. A user with "Create Entries" permission can inject the authorIds[] (or au…
- CVE-2026-28782MEDIUMCVSS 4.3EG 4.3✓ Fixed in 4.17.0-beta.12026-03-04
vulnerable: 4.0.0 ... 4.9.7 (229 versions)
Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, the "Duplicate" entry action does not properly verify if the user has permission to perform this action on the specific target elements. Even with only "V…
- CVE-2026-28783CRITICALCVSS 9.1EG 9.1✓ Fixed in 4.17.0-beta.12026-03-04
vulnerable: 4.0.0 ... 4.9.7 (229 versions)
Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerous PHP functions from being called via Twig non-Closure arrow functions. In order to be abl…
- CVE-2026-28784HIGHCVSS 7.2EG 7.2✓ Fixed in 4.17.0-beta.12026-03-04
vulnerable: 4.0.0 ... 4.9.7 (229 versions)
Craft is a content management system (CMS). Prior to 5.8.22 and 4.16.18, it is possible to craft a malicious payload using the Twig map filter in text fields that accept Twig input under Settings in the Craft control panel or using the Sys…
- CVE-2026-29069MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.17.0-beta.22026-03-04
vulnerable: 4.0.0 ... 4.9.7 (230 versions)
Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() endpoint is accessible to unauthenticated users and does not require a permission check for pending users. An attacker wit…
- CVE-2026-29113MEDIUMCVSS 4.3EG 4.3✓ Fixed in 5.9.72026-03-10
vulnerable: 5.0.0 ... 5.9.6 (154 versions)
Craft is a content management system (CMS). Prior to 4.17.4 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action do…
- CVE-2026-31857HIGHCVSS 8.8EG 8.8✓ Fixed in 4.17.42026-03-11
vulnerable: 4.0.0 ... 4.9.7 (239 versions)
Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The BaseElementSelectConditionRule::getElementIds() method passes user-controlled str…
- CVE-2026-31858HIGHCVSS 8.8EG 8.8✓ Fixed in 5.9.92026-03-11
vulnerable: 5.0.0 ... 5.9.8 (156 versions)
Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() protection that was added to ElementIndexesController in CVE-2026-25495. The exact same SQL injection vulnerability (in…
- CVE-2026-31859MEDIUMCVSS 6.1EG 6.1✓ Fixed in 5.9.72026-03-11
vulnerable: 5.7.10 ... 5.9.6 (44 versions)
Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize return URLs before they are stored in the session. However, strip_tags() only removes HTM…
- CVE-2026-32262MEDIUMCVSS 4.3EG 4.3✓ Fixed in 5.9.112026-03-16
vulnerable: 5.0.0 ... 5.9.9 (158 versions)
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, the AssetsController->replaceFile() method has a targetFilename body parameter that is use…
- CVE-2026-32263HIGHCVSS 7.2EG 7.2✓ Fixed in 5.9.112026-03-16
vulnerable: 5.6.0 ... 5.9.9 (80 versions)
Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTypesController.php, the $settings array from parse_str is passed directly to Craft::configure() without Component::cleans…
- CVE-2026-32264HIGHCVSS 7.2EG 7.2✓ Fixed in 5.9.112026-03-16
vulnerable: 5.0.0 ... 5.9.9 (158 versions)
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, there is a Behavior injection RCE vulnerability in ElementIndexesController and FieldsCont…
- CVE-2026-32267CRITICALCVSS 9.8EG 9.8✓ Fixed in 5.9.122026-03-16
vulnerable: 5.0.0 ... 5.9.9 (159 versions)
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escal…
- CVE-2026-33051MEDIUMCVSS 5.4EG 5.4✓ Fixed in 5.9.112026-03-20
vulnerable: 5.9.0 ... 5.9.9 (13 versions)
Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor renders the creator’s fullName as raw HTML due to the use of Template::raw() combined with Cra…
- CVE-2026-33157HIGHCVSS 7.2EG 7.2✓ Fixed in 5.9.132026-03-24
vulnerable: 5.6.0 ... 5.9.9 (82 versions)
Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.13, a Remote Code Execution (RCE) vulnerability exists in Craft CMS, it can be exploited by any authenticated user with control panel access. This is …
- CVE-2026-33158MEDIUMCVSS 6.5EG 6.5✓ Fixed in 5.9.142026-03-24
vulnerable: 5.0.0 ... 5.9.9 (161 versions)
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can read private asset content by calling assets/edit-…
- CVE-2026-33159MEDIUMCVSS 6.5EG 6.5✓ Fixed in 4.17.82026-03-24
vulnerable: 4.0.0 ... 4.9.7 (239 versions)
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, guest users can access Config Sync updater index, obtain signed data, and execute state-ch…
- CVE-2026-33160MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.17.82026-03-24
vulnerable: 4.0.0 ... 4.9.7 (239 versions)
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, an unauthenticated user can call assets/generate-transform with a private assetId, receive…
- CVE-2026-33161MEDIUMCVSS 4.3EG 4.3✓ Fixed in 4.17.82026-03-24
vulnerable: 4.0.0 ... 4.9.7 (239 versions)
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can call assets/image-editor with the ID of a private …
- CVE-2026-33162MEDIUMCVSS 6.5EG 6.5✓ Fixed in 5.9.142026-03-24
vulnerable: 5.3.0 ... 5.9.9 (122 versions)
Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/entries/move-to-section, even when they …
- CVE-2026-41128MEDIUMCVSS 5.3EG 5.3✓ Fixed in 5.9.152026-04-22
vulnerable: 5.6.0 ... 5.9.9 (84 versions)
Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups(…
- CVE-2026-41129MEDIUMCVSS 5.5EG 5.5✓ Fixed in 4.17.92026-04-22
vulnerable: 4.0.0 ... 4.9.7 (240 versions)
Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the use…
- CVE-2026-41130MEDIUMCVSS 5.5EG 5.5✓ Fixed in 4.17.92026-04-22
vulnerable: 4.0.0 ... 4.9.7 (240 versions)
Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources. …
- CVE-2026-44010HIGHCVSS 7.1EG 7.1✓ Fixed in 4.17.122026-05-12
vulnerable: 4.0.0 ... 4.9.7 (240 versions)
Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element resolver (src/gql/resolvers/elements/Address.php) performs no schema scope filtering on top-level queries. A GraphQL API t…
- CVE-2026-44011HIGHCVSS 8.6EG 8.6✓ Fixed in 5.9.182026-05-12
vulnerable: 5.0.0 ... 5.9.9 (164 versions)
Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an input-handling flaw in a Yii object creation path that let any authenticated user inject malicious configuration and execu…
- CVE-2026-44012HIGHCVSS 7.1EG 7.1✓ Fixed in 5.9.182026-05-12
vulnerable: 5.0.0 ... 5.9.9 (165 versions)
Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() fetches an asset by ID and returns its filename and complete folder hierarchy (including volume handle, volume UID, fol…
- CVE-2026-50279HIGHCVSS 7.6EG 7.6✓ Fixed in 5.9.212026-07-02
vulnerable: 5.0.0 ... 5.9.9 (168 versions)
Craft CMS is a content management system (CMS). IN versions 5.0.0-RC1 and above prior to 5.9.21, theEntriesController::actionSaveEntry() performs entry-edit permission checks before request-controlled author changes are applied to the mode…
- CVE-2026-50280MEDIUMCVSS 6.0EG 6.0✓ Fixed in 5.9.212026-07-02
vulnerable: 5.0.0 ... 5.9.9 (168 versions)
Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 and above prior to 5.9.21, the EntriesController::actionMoveToSection() endpoint gates the destination section only by viewEntries:$section->uid rather than requiring sa…
Check whether craftcms/cms is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for craftcms/cms CVEs against the assets you own.
Start Free Scan →