Vulnerability index

Browse CVEs

91 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-33162 Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp c… Craft Cms 5.9.14+ Fix from $1,6002026-03-24 MEDIUM 5.3 CVE-2026-33160 Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, … Craft Cms 4.17.8 / 5.9.14+ Fix from $1,6002026-03-24 HIGH 7.2 CVE-2026-33157 Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.13, a Remote Code Execution (RCE) vulnerability exists in Cr… Craft Cms 5.9.13+ Fix from $1,9502026-03-24 MEDIUM 6.5 CVE-2026-33158 Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, … Craft Cms 4.17.8 / 5.9.14+ Fix from $1,6002026-03-24 MEDIUM 6.5 CVE-2026-33159 Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, … Craft Cms 4.17.8 / 5.9.14+ Fix from $1,6002026-03-24 MEDIUM 5.4 CVE-2026-33051 Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor render… Craft Cms 5.9.11+ Fix from $1,6002026-03-20 CRITICAL 9.8 CVE-2026-32267EPSS 8% Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, … Craft Cms 4.17.6 / 5.9.12+ Fix from $2,3002026-03-16 HIGH 7.2 CVE-2026-32263 Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTypesController.php, the $settin… Craft Cms 5.9.11+ Fix from $1,9502026-03-16 HIGH 7.2 CVE-2026-32264 Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, … Craft Cms 4.17.5 / 5.9.11+ Fix from $1,9502026-03-16 HIGH 8.8 CVE-2026-31857 Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions sys… Craft Cms 4.17.4 / 5.9.9+ Fix from $1,9502026-03-11 HIGH 8.8 CVE-2026-31858 Craft is a content management system (CMS). The ElementSearchController::actionSearch() endpoint is missing the unset() protection that was added to … Craft Cms 5.9.9+ Fix from $1,9502026-03-11 MEDIUM 6.1 CVE-2026-31859 Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize… Craft Cms 4.17.3 / 5.9.7+ Fix from $1,6002026-03-11 MEDIUM 5.4 CVE-2026-29177 Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Cra… Craft Commerce 4.10.2 / 5.5.3+ Fix from $1,6002026-03-10 HIGH 8.8 CVE-2026-29172 Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, Craft Commerce is vulnerable to SQL Injection in the purchasables t… Craft Commerce 4.10.2 / 5.5.3+ Fix from $1,9502026-03-10 HIGH 8.8 CVE-2026-29174 Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in the inventory levels table da… Craft Commerce 5.5.3+ Fix from $1,9502026-03-10 MEDIUM 5.4 CVE-2026-29175 Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Stored XSS vulnerabilities exist in the Commerce Inventory page. The Product T… Craft Commerce 5.5.3+ Fix from $1,6002026-03-10 MEDIUM 5.3 CVE-2026-29069 Craft is a content management system (CMS). Prior to 5.9.0-beta.2 and 4.17.0-beta.2, the actionSendActivationEmail() endpoint is accessible to unauth… Craft Cms 4.17.0 / 5.9.0+ Fix from $1,6002026-03-04 CRITICAL 9.1 CVE-2026-28697 Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution… Craft Cms 4.17.0 / 5.9.0+ Fix from $2,3002026-03-04 CRITICAL 9.1 CVE-2026-28783 Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerou… Craft Cms 4.17.0 / 5.9.0+ Fix from $2,3002026-03-04 HIGH 7.5 CVE-2026-28696 Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the GraphQL directive @parseRefs, intended to parse internal ref… Craft Cms 4.17.0 / 5.9.0+ Fix from $1,9502026-03-04 HIGH 7.2 CVE-2026-28784 Craft is a content management system (CMS). Prior to 5.8.22 and 4.16.18, it is possible to craft a malicious payload using the Twig map filter in tex… Craft Cms 4.17.0 / 5.9.0+ Fix from $1,9502026-03-04 MEDIUM 6.5 CVE-2026-28781 Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, the entry creation process allows for Mass Assignment of the aut… Craft Cms 4.17.0 / 5.9.0+ Fix from $1,6002026-03-04 HIGH 7.2 CVE-2026-28695 Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Template Injection using the crea… Craft Cms 4.17.0 / 5.9.0+ Fix from $1,9502026-03-04 MEDIUM 6.5 CVE-2026-27129 Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s Gr… Craft Cms 4.16.19 / 5.8.23+ Fix from $1,6002026-02-24 MEDIUM 6.3 CVE-2026-27127 Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s Gr… Craft Cms 4.16.19 / 5.8.23+ Fix from $1,6002026-02-24 HIGH 8.8 CVE-2026-25495 Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/g… Craft Cms 4.16.18 / 5.8.22+ Fix from $1,9502026-02-09 HIGH 8.8 CVE-2026-25497 Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege… Craft Cms 4.17.0 / 5.9.0+ Fix from $1,9502026-02-09 HIGH 7.2 CVE-2026-25498 Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a Remote Code Execution (RC… Craft Cms 4.16.18 / 5.8.22+ Fix from $1,9502026-02-09 MEDIUM 6.5 CVE-2026-25492 Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save_images_Asset GraphQL mutatio… Craft Cms 4.16.18 / 5.8.22+ Fix from $1,6002026-02-09 MEDIUM 6.5 CVE-2026-25493 Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQL… Craft Cms 4.16.18 / 5.8.22+ Fix from $1,6002026-02-09