Vulnerability index

Browse CVEs

91 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Craft Cms MEDIUM 6.5
CVE-2026-25494

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQ…

Fix: 4.16.18 / 5.8.22+
Fix from $1,600 2026-02-09
Craft Commerce MEDIUM 5.4
CVE-2026-25483

Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability exist…

Fix: 4.10.1 / 5.5.2+
Fix from $1,600 2026-02-03
Craft Cms CRITICAL 9.1
CVE-2025-68456

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trig…

Fix: 4.16.17 / 5.8.21+
Fix from $2,300 2026-01-05
Craft Cms HIGH 8.8
CVE-2025-68454

Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential aut…

Fix: 4.16.17 / 5.8.21+
Fix from $1,950 2026-01-05
Craft Cms HIGH 7.2
CVE-2025-68455

Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential aut…

Fix: 4.16.17 / 5.8.21+
Fix from $1,950 2026-01-05
Craft Cms MEDIUM 6.8
CVE-2025-68437

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save…

Fix: 4.16.17 / 5.8.21+
Fix from $1,600 2026-01-05
Craft Cms MEDIUM 6.5
CVE-2025-68436

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Cr…

Fix: 4.16.17 / 5.8.21+
Fix from $1,600 2026-01-05
Craft Cms HIGH 7.2
CVE-2025-57811

Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code exec…

Fix: 4.16.6 / 5.8.7+
Fix from $1,950 2025-08-25
Craft Cms HIGH 8.8
CVE-2025-54417

Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass …

Fix: 4.16.3 / 5.8.4+
Fix from $1,950 2025-08-09
Craft Cms MEDIUM 5.3
CVE-2025-35939 KEV

Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an…

Fix: 4.15.3 / 5.7.5+
Fix from $1,600 2025-05-07
Craft Cms HIGH 7.2
CVE-2025-46731

Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a poten…

Fix: 4.14.13 / 5.6.15+
Fix from $1,950 2025-05-05
Craft Cms CRITICAL 10.0
CVE-2025-32432 KEVEPSS 100%

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.1…

Fix: 3.9.15 / 4.14.15+
Fix from $2,300 2025-04-25
Craft Cms HIGH 8.1
CVE-2025-23209 KEV

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerab…

Fix: 4.13.8 / 5.5.8+
Fix from $1,950 2025-01-18
Craft Cms CRITICAL 9.8
CVE-2024-56145 KEVEPSS 97%

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this…

Fix: 3.9.14 / 4.13.2+
Fix from $2,300 2024-12-18
Craft Cms HIGH 7.2
CVE-2024-52291

Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a doub…

Fix: 4.12.5 / 5.4.6+
Fix from $1,950 2024-11-13
Craft Cms MEDIUM 6.5
CVE-2024-52292

Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templat…

Fix: 4.12.8 / 5.4.9+
Fix from $1,600 2024-11-13
Craft Cms HIGH 7.2
CVE-2024-52293

Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could …

Fix: 4.12.2 / 5.4.3+
Fix from $1,950 2024-11-13
Craft Cms HIGH 7.5
CVE-2024-41800

Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to…

Fix: 5.2.3+
Fix from $1,950 2024-07-25
Craft Cms CRITICAL 9.8
CVE-2024-37843EPSS 53%

Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.

Fix: 3.7.31+
Fix from $2,300 2024-06-25
Craft Cms HIGH 7.5
CVE-2023-36260

An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings …

Fix: 4.6.1.1+
Fix from $1,950 2024-01-30
Craft Cms MEDIUM 5.4
CVE-2023-36259

Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creati…

Fix: 3.0.2+
Fix from $1,600 2024-01-30
Craft Cms HIGH 8.8
CVE-2024-21622

Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x…

Fix: 3.9.6+
Fix from $1,950 2024-01-03
Craft Cms CRITICAL 9.8
CVE-2023-41892EPSS 93%

Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations befo…

Fix: 4.4.15+
Fix from $2,300 2023-09-13
Craft Cms HIGH 7.2
CVE-2023-40035

Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code e…

Fix: 3.8.15 / 4.4.15+
Fix from $1,950 2023-08-23
Craft Cms MEDIUM 6.1
CVE-2023-33495

Craft CMS through 4.4.9 is vulnerable to HTML Injection.

Fix: after 4.4.9
Fix from $1,600 2023-06-20
Craft Cms HIGH 7.2
CVE-2023-30179

CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Loca…

Patch available
Fix from $1,950 2023-06-13
Craft Cms MEDIUM 6.1
CVE-2023-33195

Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This issue was patched in version…

Fix: 4.4.6+
Fix from $1,600 2023-05-27
Craft Cms MEDIUM 5.4
CVE-2023-33196

Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in v…

Fix: 4.4.7+
Fix from $1,600 2023-05-26
Craft Cms MEDIUM 5.4
CVE-2023-33197

Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. Th…

Fix: 4.4.6+
Fix from $1,600 2023-05-26
Craft Cms MEDIUM 5.4
CVE-2023-2817

A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected i…

Fix: after 4.4.11
Fix from $1,600 2023-05-26