craftcms/cms
Packagist125 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting craftcms/cmspage 3 of 3
- CVE-2026-50281HIGHCVSS 7.1EG 7.1✓ Fixed in 5.9.212026-07-02
vulnerable: 5.7.0 ... 5.9.9 (64 versions)
Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw in the bulk-duplicate element action. An attacker who is only able to duplicate their own entires can submit an arbitr…
- CVE-2026-50282HIGHEG not assessed✓ Fixed in 4.17.142026-07-02
vulnerable: 4.0.0 ... 4.9.7 (246 versions)
Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves We have identified an authorization issue in Craft CMS where a forced folder move can delete a conflicting destination folder without destination del…
- CVE-2026-50283MEDIUMCVSS 5.3EG 5.3✓ Fixed in 4.17.142026-07-01
vulnerable: 4.0.0 ... 4.9.7 (246 versions)
Craft CMS is a content management system (CMS). Versions 5.0.0-RC1 through 5.9.20, and 4.0.0-RC1 through 4.17.13 contain an authorization issue in the AssetsController::actionReplaceFile that can delete a source asset without source delete…
- CVE-2026-50284HIGHCVSS 7.1EG 7.1✓ Fixed in 4.17.152026-07-01
vulnerable: 4.0.0 ... 4.9.7 (247 versions)
Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.21 and 4.0.0-RC1 through 4.17.14, theAssetsController::actionDeleteFolder() only requires the deleteAssets:<volume-uid> permission for the target folder. It …
- CVE-2026-55790HIGHCVSS 7.4EG 7.4✓ Fixed in 4.17.162026-07-01
vulnerable: 4.0.0 ... 4.9.7 (248 versions)
Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22 and 4.0.0-RC1 through 4.17.15, an attacker with only a GitHub account can plant a JavaScript payload in a craftcms/cms issue title. When a Craft admin use…
- CVE-2026-55791MEDIUMCVSS 6.9EG 6.9✓ Fixed in 4.182026-06-19
vulnerable: 4.0.0 ... 4.9.7 (249 versions)
Craft CMS is a content management system (CMS). Versions 4.0.0-RC1 and above, prior to 4.18.0 and 5.0.0-RC1, and above, prior to 5.10.0, are vulnerable to Server-Side Request Forgery (SSRF) and Arbitrary JavaScript Injection through the /a…
- CVE-2026-55792MEDIUMCVSS 6.0EG 6.0✓ Fixed in 5.10.02026-07-02
vulnerable: 5.0.0 ... 5.9.9 (171 versions)
Craft CMS is a content management system (CMS). In versions starting from 4.0.0-RC1 and prior to 4.18.0, and 5.0.0-RC1 and above, prior to 5.10.0, the dataUrl() Twig function is included in Craft’s Twig sandbox allowlist, allowing any co…
- CVE-2026-55793MEDIUMCVSS 5.9EG 5.9✓ Fixed in 5.9.532026-07-01
vulnerable: 5.0.0 ... 5.9.9 (171 versions)
Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.22, an author-level control panel user can store a malicious JavaScript payload in an entry title. When an admin, or any control panel user with saveEntries …
- CVE-2026-55794HIGHCVSS 8.7EG 8.7✓ Fixed in 5.10.02026-07-02
vulnerable: 5.9.0 ... 5.9.9 (24 versions)
Craft CMS is a content management system (CMS). In versions 5.9.0 and above prior to 5.10.0, control panel users with the ability to edit entries can execute unsandboxed Twig code via the HTTP Referrer header, potentially leading to authen…
- CVE-2026-56381MEDIUMCVSS 4.8EG 4.8✓ Fixed in 5.8.222026-06-21
vulnerable: 5.0.0 ... 5.8.9 (143 versions)
Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where user group names are rendered without proper HTML escaping. Attackers with admin access can inject arbitrary JavaScrip…
- CVE-2026-56382HIGHCVSS 7.2EG 7.2✓ Fixed in 5.9.142026-06-21
vulnerable: 5.5.0 ... 5.9.9 (97 versions)
Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in the FieldsController::actionRenderCardPreview() method, which passes the fieldLayoutConfig POST parameter directly t…
- CVE-2026-56383MEDIUMCVSS 4.8EG 4.8✓ Fixed in 5.8.232026-06-21
vulnerable: 5.0.0 ... 5.8.9 (144 versions)
Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the 'Row Heading' column type. The application fails to sanitize input within row heading default values, allowing an attac…
- CVE-2026-56384MEDIUMCVSS 4.3EG 4.3✓ Fixed in 5.9.142026-06-21
vulnerable: 5.0.0 ... 5.9.9 (161 versions)
Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a target private asset can call the endpoint with an attacker-controlled assetId and receive pre…
- CVE-2026-56385MEDIUMCVSS 4.3EG 4.3✓ Fixed in 4.17.82026-06-21
vulnerable: 4.0.0 ... 4.9.7 (239 versions)
Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-file endpoint. The action does not enforce per-asset view authorization before returning preview content, allowing…
- CVE-2026-56393MEDIUMCVSS 4.8EG 4.8✓ Fixed in 4.17.0-beta.12026-06-21
vulnerable: 4.0.0 ... 4.9.7 (229 versions)
Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rendered without sanitization (e.g., via the…
- CVE-2026-56394MEDIUMCVSS 6.5EG 6.5✓ Fixed in 5.9.132026-06-21
vulnerable: 5.0.0 ... 5.9.9 (160 versions)
Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can bypass extension validation by passing t…
- CVE-2026-72778HIGHCVSS 8.8EG 8.8✓ Fixed in 5.10.62026-08-11
vulnerable: 5.0.0 ... 5.9.9 (178 versions)
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition handling. Craft cleanses the outer request-controll…
- CVE-2026-72779MEDIUMCVSS 4.5EG 4.5✓ Fixed in 5.10.62026-08-11
vulnerable: 5.0.0 ... 5.9.9 (178 versions)
Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create() Twig function restricts class instantiation using a 5-entry blocklist that does not include SplFileObject, allowing an…
- CVE-2026-72780MEDIUMCVSS 6.5EG 6.5✓ Fixed in 5.10.52026-08-11
vulnerable: 5.0.0 ... 5.9.9 (177 versions)
Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can replay captured login request bodies containing requestOptions and response to create add…
- CVE-2026-72781HIGHCVSS 8.8EG 8.8✓ Fixed in 5.10.72026-08-11
vulnerable: 5.0.0 ... 5.9.9 (179 versions)
Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechanism. Because Craft marks the ElementInterface as safe (via the AllowedInSandbox attribute)…
- CVE-2026-72782MEDIUMCVSS 6.5EG 6.5✓ Fixed in 5.10.62026-08-11
vulnerable: 5.0.0 ... 5.9.9 (178 versions)
Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (via ${ENV_VAR} strings in the elementId parameter) into Twig templates before rendering, even when the Twig sandbox…
- CVE-2026-72783MEDIUMCVSS 6.2EG 6.2✓ Fixed in 5.10.62026-08-11
vulnerable: 5.0.0 ... 5.9.9 (178 versions)
Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContained function of the Local file system class. The order of operations validates the path bef…
- CVE-2026-72785MEDIUMCVSS 4.3EG 4.3✓ Fixed in 5.10.62026-08-11
vulnerable: 5.0.0 ... 5.9.9 (178 versions)
Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can permanently modify that group's categor…
- CVE-2026-72786MEDIUMCVSS 6.5EG 6.5✓ Fixed in 5.10.82026-08-12
vulnerable: 5.0.0 ... 5.9.9 (180 versions)
Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission can reset any user's…
- CVE-2026-72787MEDIUMCVSS 6.4EG 6.4✓ Fixed in 5.10.82026-08-12
vulnerable: 5.0.0 ... 5.9.9 (180 versions)
Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can create element drafts c…
Check whether craftcms/cms is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for craftcms/cms CVEs against the assets you own.
Start Free Scan →