Vulnerability index

Browse CVEs

91 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Craft Cms MEDIUM 6.5
CVE-2026-33162

Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp c…

Fix: 5.9.14+
Fix from $1,600 2026-03-24
Craft Cms MEDIUM 5.3
CVE-2026-33160

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, …

Fix: 4.17.8 / 5.9.14+
Fix from $1,600 2026-03-24
Craft Cms HIGH 7.2
CVE-2026-33157

Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.13, a Remote Code Execution (RCE) vulnerability exists in Cr…

Fix: 5.9.13+
Fix from $1,950 2026-03-24
Craft Cms MEDIUM 6.5
CVE-2026-33158

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, …

Fix: 4.17.8 / 5.9.14+
Fix from $1,600 2026-03-24
Craft Cms MEDIUM 6.5
CVE-2026-33159

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, …

Fix: 4.17.8 / 5.9.14+
Fix from $1,600 2026-03-24
Craft Cms MEDIUM 5.4
CVE-2026-33051

Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor render…

Fix: 5.9.11+
Fix from $1,600 2026-03-20
Craft Cms CRITICAL 9.8
CVE-2026-32267EPSS 8%

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, …

Fix: 4.17.6 / 5.9.12+
Fix from $2,300 2026-03-16
Craft Cms HIGH 7.2
CVE-2026-32263

Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTypesController.php, the $settin…

Fix: 5.9.11+
Fix from $1,950 2026-03-16
Craft Cms HIGH 7.2
CVE-2026-32264

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, …

Fix: 4.17.5 / 5.9.11+
Fix from $1,950 2026-03-16
Craft Cms HIGH 8.8
CVE-2026-31857

Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions sys…

Fix: 4.17.4 / 5.9.9+
Fix from $1,950 2026-03-11
Craft Cms HIGH 8.8
CVE-2026-31858

Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() protection that was added to …

Fix: 5.9.9+
Fix from $1,950 2026-03-11
Craft Cms MEDIUM 6.1
CVE-2026-31859

Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize…

Fix: 4.17.3 / 5.9.7+
Fix from $1,600 2026-03-11
Craft Commerce MEDIUM 5.4
CVE-2026-29177

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Cra…

Fix: 4.10.2 / 5.5.3+
Fix from $1,600 2026-03-10
Craft Commerce HIGH 8.8
CVE-2026-29172

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, Craft Commerce is vulnerable to SQL Injection in the purchasables t…

Fix: 4.10.2 / 5.5.3+
Fix from $1,950 2026-03-10
Craft Commerce HIGH 8.8
CVE-2026-29174

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in the inventory levels table da…

Fix: 5.5.3+
Fix from $1,950 2026-03-10
Craft Commerce MEDIUM 5.4
CVE-2026-29175

Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Stored XSS vulnerabilities exist in the Commerce Inventory page. The Product T…

Fix: 5.5.3+
Fix from $1,600 2026-03-10
Craft Cms MEDIUM 5.3
CVE-2026-29069

Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() endpoint is accessible to unauth…

Fix: 4.17.0 / 5.9.0+
Fix from $1,600 2026-03-04
Craft Cms CRITICAL 9.1
CVE-2026-28697

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution…

Fix: 4.17.0 / 5.9.0+
Fix from $2,300 2026-03-04
Craft Cms CRITICAL 9.1
CVE-2026-28783

Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerou…

Fix: 4.17.0 / 5.9.0+
Fix from $2,300 2026-03-04
Craft Cms HIGH 7.5
CVE-2026-28696

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal ref…

Fix: 4.17.0 / 5.9.0+
Fix from $1,950 2026-03-04
Craft Cms HIGH 7.2
CVE-2026-28784

Craft is a content management system (CMS). Prior to 5.8.22 and 4.16.18, it is possible to craft a malicious payload using the Twig map filter in tex…

Fix: 4.17.0 / 5.9.0+
Fix from $1,950 2026-03-04
Craft Cms MEDIUM 6.5
CVE-2026-28781

Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the aut…

Fix: 4.17.0 / 5.9.0+
Fix from $1,600 2026-03-04
Craft Cms HIGH 7.2
CVE-2026-28695

Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Template Injection using the crea…

Fix: 4.17.0 / 5.9.0+
Fix from $1,950 2026-03-04
Craft Cms MEDIUM 6.5
CVE-2026-27129

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s Gr…

Fix: 4.16.19 / 5.8.23+
Fix from $1,600 2026-02-24
Craft Cms MEDIUM 6.3
CVE-2026-27127

Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s Gr…

Fix: 4.16.19 / 5.8.23+
Fix from $1,600 2026-02-24
Craft Cms HIGH 8.8
CVE-2026-25495

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/g…

Fix: 4.16.18 / 5.8.22+
Fix from $1,950 2026-02-09
Craft Cms HIGH 8.8
CVE-2026-25497

Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege…

Fix: 4.17.0 / 5.9.0+
Fix from $1,950 2026-02-09
Craft Cms HIGH 7.2
CVE-2026-25498

Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a Remote Code Execution (RC…

Fix: 4.16.18 / 5.8.22+
Fix from $1,950 2026-02-09
Craft Cms MEDIUM 6.5
CVE-2026-25492

Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save_images_Asset GraphQL mutatio…

Fix: 4.16.18 / 5.8.22+
Fix from $1,600 2026-02-09
Craft Cms MEDIUM 6.5
CVE-2026-25493

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL…

Fix: 4.16.18 / 5.8.22+
Fix from $1,600 2026-02-09