vciy

CVEs we hold for Craftcms

Records whose assigning authority named Craftcms as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-92594Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQLcraftcms cms
CVE-2026-92593Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Executioncraftcms cms
CVE-2026-92592Craft CMS before 4.18.6 Remote Code Execution via signed cookiecraftcms cms
CVE-2026-92591Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installercraftcms cms
CVE-2026-92590Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fieldscraftcms cms
CVE-2026-92589Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reordercraftcms cms
CVE-2026-86732Craft CMS before 5.10.12 Remote Code Execution via element-indexcraftcms cms
CVE-2026-86731Craft CMS 5.0.0-RC1 before 5.10.12 Permission Escalation via UsersControllercraftcms cms
CVE-2026-86730Craft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCEcraftcms cms
CVE-2026-84802Craft CMS 5.7.0 before 5.10.12 Information Disclosure via AssetsControllercraftcms cms
CVE-2026-84801Craft CMS 5.0.0-RC1 before 5.10.11 Authentication Bypass via administrateUserscraftcms cms
CVE-2026-84800Craft CMS 5.0.0-RC1 before 5.10.11 File Overwrite via assets/replace-filecraftcms cms
CVE-2026-84799Craft CMS before 5.11.0 PII Disclosure via GraphQL User Relationscraftcms cms
CVE-2026-84798Craft CMS before 5.10.11 Authorization Bypass via actionDeleteForSitecraftcms cms
CVE-2026-84797Craft CMS 5.0.0-RC1 before 5.10.11 Authorization Bypass via actionDuplicatecraftcms cms
CVE-2026-84796Craft CMS 5.0.0-RC1 before 5.10.11 GraphQL Entry Mutation Site Scope Bypasscraftcms cms
CVE-2026-84795Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritancecraftcms cms
CVE-2026-84794Craft CMS 5.0.0 through 5.10.10 Authorization Bypass via assets/move-assetcraftcms cms
CVE-2026-84793Craft CMS 5.0.0-RC1 before 5.10.11 Stored XSS via site namecraftcms cms
CVE-2026-84792Craft CMS before 5.10.11 Broken Access Control via element-indexescraftcms cms
CVE-2026-79991Authenticated SQL Injection via nested eager-loading criteriacraftcms cms
CVE-2026-79990GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/deletecraftcms cms
CVE-2026-79989Arbitrary user password reset leading to administrator account takeovercraftcms cms
CVE-2026-79988Authenticated RCE through Twig sandbox escapecraftcms cms
CVE-2026-79987Low-privilege RCE through element-search eager loadingcraftcms cms
CVE-2026-78416Authenticated RCE via `condition.config` JSON cleanse bypasscraftcms cms
CVE-2026-72787Craft CMS 5.0.0-RC1 before 5.10.8 Stored XSS via Draft Namecraftcms cms
CVE-2026-72786Craft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password Resetcraftcms cms
CVE-2026-72785Craft CMS before 5.10.6 Authorization Bypass via structures/move-elementcraftcms cms
CVE-2026-72784Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutationcraftcms cms
CVE-2026-72783Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContainedcraftcms cms
CVE-2026-72782Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leakcraftcms cms
CVE-2026-72781Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escapecraftcms cms
CVE-2026-72780Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkeycraftcms cms
CVE-2026-72779Craft CMS 5.0.0-RC1 before 5.10.6 Arbitrary File Read via SplFileObjectcraftcms cms
CVE-2026-72778Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.configcraftcms cms
CVE-2026-56394Craft CMS - Authenticated Path Traversal in assets/icon Extension Parametercraftcms cms
CVE-2026-56393Craft CMS - Multiple Stored Cross-Site Scripting in Settings Names and Field Optionscraftcms cms
CVE-2026-56385Craft CMS - Authorization Bypass in assets/preview-file Endpointcraftcms cms
CVE-2026-56384Craft CMS - Missing Authorization in assets/preview-thumb Endpointcraftcms cms
CVE-2026-56383Craft CMS - Stored XSS in Table Field via Row Heading Column Typecraftcms cms
CVE-2026-56382Craft CMS - Remote Code Execution via Missing Config Sanitization in FieldsControllercraftcms cms
CVE-2026-56381Craft CMS - Stored XSS via User Group Name in User Permissions Pagecraftcms cms
CVE-2026-55795Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypasscraftcms commerce
CVE-2026-55794Craft CMS: Potential authenticated Remote Code Execution via referrer redirectcraftcms cms
CVE-2026-55793Craft CMS: Stored XSS via Structure entry title in table viewcraftcms cms
CVE-2026-55792Craft CMS: Sensitive File Disclosure / Server-Side File Readcraftcms cms
CVE-2026-55791Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJscraftcms cms
CVE-2026-55790Craft CMS: DOM XSS via GitHub issue title in CraftSupport widgetcraftcms cms
CVE-2026-50284Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users'…craftcms cms
CVE-2026-50283Craft CMS: Unauthorized Deletion of Source Assets During File Replacementcraftcms cms
CVE-2026-50282Craft CMS: Unauthorized Deletion of Destination Folders During Forced Movescraftcms cms
CVE-2026-50281Craft CMS: Mass assignment via id in newAttributes during bulk duplicate overwrites existing elementscraftcms cms
CVE-2026-50280Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save checkcraftcms cms
CVE-2026-50279Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gapcraftcms cms
CVE-2026-44012Craft CMS: Missing Volume Permission Check in AssetsController::actionShowInFolder Allows Information Disclosurecraftcms cms
CVE-2026-44011Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behaviorcraftcms cms
CVE-2026-44010Craft CMS: Missing Authorization in GraphQL Address Resolver Allows Cross-Scope PII Disclosurecraftcms cms
CVE-2026-41130Craft CMS has a host header injection leading to SSRF via resource-js endpointcraftcms cms
CVE-2026-41129Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutationscraftcms cms
CVE-2026-41128Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Actioncraftcms cms
CVE-2026-33162Craft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section…craftcms cms
CVE-2026-33161Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized userscraftcms cms
CVE-2026-33160Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform URLcraftcms cms
CVE-2026-33159Craft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted…craftcms cms
CVE-2026-33158Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)craftcms cms
CVE-2026-33157Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behaviorcraftcms cms
CVE-2026-33051Craft CMS Vulnerable to Stored XSS in Revision Context Menucraftcms cms
CVE-2026-32272Craft Commerce: Blind SQL Injection via hasVariant/hasProductcraftcms commerce
CVE-2026-32271Craft Commerce: SQL Injection can lead to Remote Code Execution via TotalRevenue Widgetcraftcms commerce
CVE-2026-32270Craft Commerce: Unauthenticated information disclosure in `commerce/payments/pay` can leak some customer order data on…craftcms commerce
CVE-2026-32268Azure Blob Storage for Craft CMS Potential Sensitive Information Disclosure vulnerabilitycraftcms azure-blob
CVE-2026-32267Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()craftcms cms
CVE-2026-32266Google Cloud Storage for Craft CMS has an Information Disclosure Vulnerabilitycraftcms google-cloud
CVE-2026-32265Amazon S3 for Craft CMS has an Information Disclosure vulnerabilitycraftcms aws-s3
CVE-2026-32264Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsControllercraftcms cms
CVE-2026-32263Craft CMS vulnerable to behavior injection RCE via EntryTypesControllercraftcms cms
CVE-2026-32262Craft CMS has a Path Traversal Vulnerability in AssetsControllercraftcms cms
CVE-2026-32261RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugincraftcms webhooks
CVE-2026-31867Craft Commerce has a Potential IDOR in Commerce cartscraftcms commerce
CVE-2026-31859Craft has Reflective XSS via incomplete return URL sanitizationcraftcms cms
CVE-2026-31858CraftCMS's `ElementSearchController` Affected by Blind SQL Injectioncraftcms cms
CVE-2026-31857CraftCMS has an RCE vulnerability via relational conditionals in the control panelcraftcms cms
CVE-2026-29177Craft Commerce has Stored XSS in Craft Commerce Order Details Slideoutcraftcms commerce
CVE-2026-29176Craft Commerce has Stored XSS in Inventory Location Namecraftcms commerce
CVE-2026-29175Multiple Stored XSS in Commerce Inventory Page Leading to Session Hijackingcraftcms commerce
CVE-2026-29174Craft Commerce has a SQL Injection in Commerce Inventory Table Sortingcraftcms commerce
CVE-2026-29173Craft Commerce has Stored XSS while updating Order Status from Orders Tablecraftcms commerce
CVE-2026-29172Craft Commerce has a SQL Injection in Commerce Purchasables Table Sortingcraftcms commerce
CVE-2026-29113Craft has a potential information disclosure vulnerability in preview tokenscraftcms cms
CVE-2026-29069Craft has an unauthenticated activation email trigger with potential user enumerationcraftcms cms
CVE-2026-28784Craft is affected by potential authenticated Remote Code Execution via Twig SSTIcraftcms cms
CVE-2026-28783Craft has a Twig Function Blocklist Bypasscraftcms cms
CVE-2026-28782Craft has a Permission Bypass and IDOR in Duplicate Entry Actioncraftcms cms
CVE-2026-28781Craft Affected by Entries Authorship Spoofing via Mass Assignmentcraftcms cms
CVE-2026-28697Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templatescraftcms cms
CVE-2026-28696Craft affected by IDOR via GraphQL @parseRefscraftcms cms
CVE-2026-28695Craft affected by authenticated RCE via Twig SSTI - create() function + Symfony Process gadgetcraftcms cms
CVE-2026-27129Cloud Metadata SSRF Protection Bypass via IPv6 Resolutioncraftcms cms
CVE-2026-27128Craft CMS's race condition in Token Service potentially allows for token usage greater than the token limitcraftcms cms
CVE-2026-27127Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebindingcraftcms cms
CVE-2026-27126Craft CMS has Stored XSS in Table Field via "HTML" Column Typecraftcms cms
CVE-2026-25522Craft Commerce has Stored XSS in Shipping Zone (Name & Description) Fields Leading to Potential Privilege Escalationcraftcms commerce
CVE-2026-25498Craft has a potential authenticated Remote Code Execution via malicious attached Behaviorcraftcms cms
CVE-2026-25497Craft has a GraphQL Asset Mutation Privilege Escalationcraftcms cms
CVE-2026-25496Craft has a stored XSS in Number Prefix & Suffix Fieldscraftcms cms
CVE-2026-25495Craft has a SQL Injection in Element Indexes via criteria[orderBy]craftcms cms
CVE-2026-25494Craft has a SSRF in GraphQL Asset Mutation via Alternative IP Notationcraftcms cms
CVE-2026-25493Craft has a SSRF in GraphQL Asset Mutation via HTTP Redirectcraftcms cms
CVE-2026-25492Craft has a save_images_Asset graphql mutation can be abused to exfiltrate AWS credentials of underlying hostcraftcms cms
CVE-2026-25491Craft has a Stored XSS in Entry Types Namecraftcms cms
CVE-2026-25490Craft Commerce has Stored XSS in Inventory Location Address Leading to Potential Privilege Escalationcraftcms commerce
CVE-2026-25489Craft Commerce has Stored XSS in Tax Zones (Name & Description) Leading to Potential Privilege Escalationcraftcms commerce
CVE-2026-25488Craft Commerce has Stored XSS in Tax Categories (Name & Description) Fields Leading to Potential Privilege Escalationcraftcms commerce
CVE-2026-25487Craft CMS has Stored XSS in Tax Rates Name Leading to Potential Privilege Escalationcraftcms commerce
CVE-2026-25486Craft Commerce has Stored XSS in Shipping Methods Name Field Leading to Potential Privilege Escalationcraftcms commerce
CVE-2026-25485Craft Commerce has Stored XSS in Shipping Categories (Name & Description) Fields Leading to Potential Privilege…craftcms commerce
CVE-2026-25484Craft Commerce has Stored XSS in Product Type Namecraftcms commerce
CVE-2026-25483Craft Commerce has Stored XSS via Order Status Message with potential database exfiltrationcraftcms commerce
CVE-2026-25482Craft Commerce has Stored DOM XSS in Order Status Name (Reflects in "Recent Orders" Dashboard Widget)craftcms commerce
CVE-2025-68456Unauthenticated Craft CMS users can trigger a database backupcraftcms cms
CVE-2025-68455Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behaviorcraftcms cms
CVE-2025-68454Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTIcraftcms cms
CVE-2025-68437Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutationcraftcms cms
CVE-2025-68436Craft CMS vulnerable to potential information disclosure via unchecked asset relocationcraftcms cms
CVE-2025-57811Craft Potential Remote Code Execution via Twig SSTIcraftcms cms
CVE-2025-54417Craft contains a theoretical bypass for CVE-2025-23209craftcms cms
CVE-2025-46731Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTIcraftcms cms
CVE-2025-32432Craft CMS Allows Remote Code Executioncraftcms cms
CVE-2025-23209Potential RCE with a compromised security key in craft/cmscraftcms cms
CVE-2024-56145RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cmscraftcms cms
CVE-2024-52293Craft has a Potential Remote Code Execution via missing path normalization & Twig SSTIcraftcms cms
CVE-2024-52292Craft Allows Attackers to Read Arbitrary System Filescraftcms cms
CVE-2024-52291Craft has a Local File System Validation Bypass Leading to File Overwrite, Sensitive File Access, and Potential Code…craftcms cms
CVE-2024-45406Craft CMS stored XSS in breadcrumb list and title fieldscraftcms cms
CVE-2024-41800Craft CMS Allows TOTP Token To Stay Valid After Usecraftcms cms
CVE-2024-21622Craft CMS Privilege Escalationcraftcms cms
CVE-2023-41892Craft CMS Remote Code Execution vulnerabilitycraftcms cms
CVE-2023-40035Craft CMS vulnerable to Remote Code Execution via validatePath bypasscraftcms cms
CVE-2023-33197Craft CMS stored XSS in indexedVolumescraftcms cms
CVE-2023-33196Craft CMS stored XSS in review volumecraftcms cms
CVE-2023-33195Craft CMS XSS in RSS widget feedcraftcms cms
CVE-2023-33194CraftCMS stored XSS in Quick Post widget error messagecraftcms cms
CVE-2023-32679Remote Code Execution via unrestricted file extension in Craft CMScraftcms cms
CVE-2023-31144Craft CMS vulnerable to cross site scripting in RSS feed widgetcraftcms cms
CVE-2023-23927Craft CMS stored cross-site scripting vulnerabilitycraftcms cms
CVE-2020-37071CraftCMS 3 vCard Plugin 1.0.0 - Remote Code ExecutionCraftCMS

147 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.