Vulnerability index

Browse CVEs

91 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Craft Cms HIGH 7.2
CVE-2023-32679

Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension may lead to Remote Code Execu…

Fix: 4.4.6+
Fix from $1,950 2023-05-19
Craft Cms HIGH 8.8
CVE-2023-30130

An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.

No fix yet
Fix from $1,950 2023-05-12
Craft Cms MEDIUM 6.1
CVE-2023-31144

Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can d…

Fix: after 4.4.3
Fix from $1,600 2023-05-09
Craft Cms MEDIUM 6.1
CVE-2023-30177

CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name.

Patch available
Fix from $1,600 2023-04-25
Craft Cms MEDIUM 5.4
CVE-2023-23927

Craft is a platform for creating digital experiences. When you insert a payload inside a label name or instruction of an entry type, an cross-site sc…

Fix: 4.3.7+
Fix from $1,600 2023-03-03
Craft Cms HIGH 7.5
CVE-2022-37783

All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSR…

Fix: after 3.7.32
Fix from $1,950 2022-12-05
Craft Cms MEDIUM 5.4
CVE-2022-37246

Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the lin…

Patch available
Fix from $1,600 2022-09-21
Craft Cms MEDIUM 5.4
CVE-2022-37251

Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.

Mitigation only
Fix from $1,600 2022-09-16
Craft Cms MEDIUM 5.4
CVE-2022-37247

Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.

Patch available
Fix from $1,600 2022-09-16
Craft Cms MEDIUM 5.4
CVE-2022-37248

Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.

Patch available
Fix from $1,600 2022-09-16
Craft Cms MEDIUM 5.4
CVE-2022-37250

Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.

Patch available
Fix from $1,600 2022-09-16
Craft Cms HIGH 8.8
CVE-2022-29933

Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take ov…

Fix: after 3.7.36
Fix from $1,950 2022-05-09
Craft Cms MEDIUM 6.1
CVE-2022-28378

Craft CMS before 3.7.29 allows XSS.

Fix: 3.7.29+
Fix from $1,600 2022-04-03
Craft Cms HIGH 8.8
CVE-2021-41824

Craft CMS before 3.7.14 allows CSV injection.

Fix: 3.7.14+
Fix from $1,950 2021-09-30
Craft Cms CRITICAL 9.8
CVE-2021-27903

An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did n…

Fix: 3.6.7+
Fix from $2,300 2021-06-30
Craft Cms MEDIUM 6.1
CVE-2021-27902

An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms th…

Fix: 3.6.0+
Fix from $1,600 2021-06-30
Craft Cms MEDIUM 6.1
CVE-2021-32470

Craft CMS before 3.6.13 has an XSS vulnerability.

Fix: 3.6.13+
Fix from $1,600 2021-05-07
Craft Cms MEDIUM 5.4
CVE-2020-19626

Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/site…

Patch available
Fix from $1,600 2021-03-26
Craft Cms CRITICAL 9.8
CVE-2020-9757EPSS 73%

The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers co…

Fix: 3.3.0+
Fix from $2,300 2020-03-04
Craft Cms MEDIUM 6.1
CVE-2019-9554

In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new …

No fix yet
Fix from $1,600 2019-12-31
Craft Cms CRITICAL 9.8
CVE-2019-15929

In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a …

Fix: after 3.1.7
Fix from $2,300 2019-10-24
Craft Cms MEDIUM 6.1
CVE-2019-17496

Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.

Fix: 3.3.8+
Fix from $1,600 2019-10-11
Craft Cms MEDIUM 5.3
CVE-2019-14280EPSS 9%

In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so,…

Fix: 2.7.10 / 3.2.6+
Fix from $1,600 2019-07-26
Craft Cms MEDIUM 6.1
CVE-2019-12823

Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.

Fix: 3.1.31+
Fix from $1,600 2019-06-18
Craft Cms HIGH 7.2
CVE-2018-20465

Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated…

Fix: after 3.0.34
Fix from $1,950 2018-12-25
Craft Cms HIGH 8.8
CVE-2018-3814

Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option,…

No fix yet
Fix from $1,950 2018-01-01
Craft Cms MEDIUM 5.4
CVE-2017-9516

Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.

Fix: after 2.6.2981
Fix from $1,600 2017-06-08
Craft Cms MEDIUM 6.1
CVE-2017-8384

Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-…

Fix: after 2.6.2974
Fix from $1,600 2017-05-01
Craft Cms MEDIUM 5.3
CVE-2017-8383

Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.

Fix: after 2.6.2974
Fix from $1,600 2017-05-01
Craft Cms MEDIUM 5.3
CVE-2017-8385

Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.

Fix: after 2.6.2974
Fix from $1,600 2017-05-01