CVEs we hold for Craftcms
Records whose assigning authority named Craftcms as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-92589Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reordercraftcms cms
CVE-2026-86731Craft CMS 5.0.0-RC1 before 5.10.12 Permission Escalation via UsersControllercraftcms cms
CVE-2026-84802Craft CMS 5.7.0 before 5.10.12 Information Disclosure via AssetsControllercraftcms cms
CVE-2026-84801Craft CMS 5.0.0-RC1 before 5.10.11 Authentication Bypass via administrateUserscraftcms cms
CVE-2026-84797Craft CMS 5.0.0-RC1 before 5.10.11 Authorization Bypass via actionDuplicatecraftcms cms
CVE-2026-84796Craft CMS 5.0.0-RC1 before 5.10.11 GraphQL Entry Mutation Site Scope Bypasscraftcms cms
CVE-2026-84794Craft CMS 5.0.0 through 5.10.10 Authorization Bypass via assets/move-assetcraftcms cms
CVE-2026-79990GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/deletecraftcms cms
CVE-2026-72786Craft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password Resetcraftcms cms
CVE-2026-72783Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContainedcraftcms cms
CVE-2026-72781Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escapecraftcms cms
CVE-2026-56394Craft CMS - Authenticated Path Traversal in assets/icon Extension Parametercraftcms cms
CVE-2026-56393Craft CMS - Multiple Stored Cross-Site Scripting in Settings Names and Field Optionscraftcms cms
CVE-2026-56382Craft CMS - Remote Code Execution via Missing Config Sanitization in FieldsControllercraftcms cms
CVE-2026-55794Craft CMS: Potential authenticated Remote Code Execution via referrer redirectcraftcms cms
CVE-2026-55791Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJscraftcms cms
CVE-2026-50284Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users'…craftcms cms
CVE-2026-50282Craft CMS: Unauthorized Deletion of Destination Folders During Forced Movescraftcms cms
CVE-2026-50281Craft CMS: Mass assignment via id in newAttributes during bulk duplicate overwrites existing elementscraftcms cms
CVE-2026-50280Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save checkcraftcms cms
CVE-2026-50279Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gapcraftcms cms
CVE-2026-44012Craft CMS: Missing Volume Permission Check in AssetsController::actionShowInFolder Allows Information Disclosurecraftcms cms
CVE-2026-44011Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behaviorcraftcms cms
CVE-2026-44010Craft CMS: Missing Authorization in GraphQL Address Resolver Allows Cross-Scope PII Disclosurecraftcms cms
CVE-2026-41130Craft CMS has a host header injection leading to SSRF via resource-js endpointcraftcms cms
CVE-2026-41129Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutationscraftcms cms
CVE-2026-41128Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Actioncraftcms cms
CVE-2026-33162Craft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section…craftcms cms
CVE-2026-33161Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized userscraftcms cms
CVE-2026-33160Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform URLcraftcms cms
CVE-2026-33159Craft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted…craftcms cms
CVE-2026-33158Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)craftcms cms
CVE-2026-33157Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behaviorcraftcms cms
CVE-2026-32271Craft Commerce: SQL Injection can lead to Remote Code Execution via TotalRevenue Widgetcraftcms commerce
CVE-2026-32270Craft Commerce: Unauthenticated information disclosure in `commerce/payments/pay` can leak some customer order data on…craftcms commerce
CVE-2026-32268Azure Blob Storage for Craft CMS Potential Sensitive Information Disclosure vulnerabilitycraftcms azure-blob
CVE-2026-32267Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()craftcms cms
CVE-2026-32266Google Cloud Storage for Craft CMS has an Information Disclosure Vulnerabilitycraftcms google-cloud
CVE-2026-32264Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsControllercraftcms cms
CVE-2026-32261RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugincraftcms webhooks
CVE-2026-31857CraftCMS has an RCE vulnerability via relational conditionals in the control panelcraftcms cms
CVE-2026-29177Craft Commerce has Stored XSS in Craft Commerce Order Details Slideoutcraftcms commerce
CVE-2026-29175Multiple Stored XSS in Commerce Inventory Page Leading to Session Hijackingcraftcms commerce
CVE-2026-29174Craft Commerce has a SQL Injection in Commerce Inventory Table Sortingcraftcms commerce
CVE-2026-29173Craft Commerce has Stored XSS while updating Order Status from Orders Tablecraftcms commerce
CVE-2026-29172Craft Commerce has a SQL Injection in Commerce Purchasables Table Sortingcraftcms commerce
CVE-2026-29113Craft has a potential information disclosure vulnerability in preview tokenscraftcms cms
CVE-2026-29069Craft has an unauthenticated activation email trigger with potential user enumerationcraftcms cms
CVE-2026-28784Craft is affected by potential authenticated Remote Code Execution via Twig SSTIcraftcms cms
CVE-2026-28697Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templatescraftcms cms
CVE-2026-28695Craft affected by authenticated RCE via Twig SSTI - create() function + Symfony Process gadgetcraftcms cms
CVE-2026-27128Craft CMS's race condition in Token Service potentially allows for token usage greater than the token limitcraftcms cms
CVE-2026-25522Craft Commerce has Stored XSS in Shipping Zone (Name & Description) Fields Leading to Potential Privilege Escalationcraftcms commerce
CVE-2026-25498Craft has a potential authenticated Remote Code Execution via malicious attached Behaviorcraftcms cms
CVE-2026-25492Craft has a save_images_Asset graphql mutation can be abused to exfiltrate AWS credentials of underlying hostcraftcms cms
CVE-2026-25490Craft Commerce has Stored XSS in Inventory Location Address Leading to Potential Privilege Escalationcraftcms commerce
CVE-2026-25489Craft Commerce has Stored XSS in Tax Zones (Name & Description) Leading to Potential Privilege Escalationcraftcms commerce
CVE-2026-25488Craft Commerce has Stored XSS in Tax Categories (Name & Description) Fields Leading to Potential Privilege Escalationcraftcms commerce
CVE-2026-25487Craft CMS has Stored XSS in Tax Rates Name Leading to Potential Privilege Escalationcraftcms commerce
CVE-2026-25486Craft Commerce has Stored XSS in Shipping Methods Name Field Leading to Potential Privilege Escalationcraftcms commerce
CVE-2026-25485Craft Commerce has Stored XSS in Shipping Categories (Name & Description) Fields Leading to Potential Privilege…craftcms commerce
CVE-2026-25483Craft Commerce has Stored XSS via Order Status Message with potential database exfiltrationcraftcms commerce
CVE-2026-25482Craft Commerce has Stored DOM XSS in Order Status Name (Reflects in "Recent Orders" Dashboard Widget)craftcms commerce
CVE-2025-68455Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behaviorcraftcms cms
CVE-2025-68454Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTIcraftcms cms
CVE-2025-68437Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutationcraftcms cms
CVE-2025-68436Craft CMS vulnerable to potential information disclosure via unchecked asset relocationcraftcms cms
CVE-2025-46731Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTIcraftcms cms
CVE-2024-56145RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cmscraftcms cms
CVE-2024-52293Craft has a Potential Remote Code Execution via missing path normalization & Twig SSTIcraftcms cms
CVE-2024-52291Craft has a Local File System Validation Bypass Leading to File Overwrite, Sensitive File Access, and Potential Code…craftcms cms
147 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.