Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2026-25494
Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the saveAsset GraphQ…
Craft Cms
4.16.18 / 5.8.22+
MEDIUM 5.4
CVE-2026-25483
Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability exist…
Craft Commerce
4.10.1 / 5.5.2+
CRITICAL 9.1
CVE-2025-68456
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trig…
Craft Cms
4.16.17 / 5.8.21+
HIGH 8.8
CVE-2025-68454
Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential aut…
Craft Cms
4.16.17 / 5.8.21+
HIGH 7.2
CVE-2025-68455
Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential aut…
Craft Cms
4.16.17 / 5.8.21+
MEDIUM 6.8
CVE-2025-68437
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save…
Craft Cms
4.16.17 / 5.8.21+
MEDIUM 6.5
CVE-2025-68436
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Cr…
Craft Cms
4.16.17 / 5.8.21+
HIGH 7.2
CVE-2025-57811
Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code exec…
Craft Cms
4.16.6 / 5.8.7+
HIGH 8.8
CVE-2025-54417
Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass …
Craft Cms
4.16.3 / 5.8.4+
MEDIUM 5.3
CVE-2025-35939 KEV
Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an…
Craft Cms
4.15.3 / 5.7.5+
HIGH 7.2
CVE-2025-46731
Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a poten…
Craft Cms
4.14.13 / 5.6.15+
CRITICAL 10.0
CVE-2025-32432 KEVEPSS 100%
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.1…
Craft Cms
3.9.15 / 4.14.15+
HIGH 8.1
CVE-2025-23209 KEV
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerab…
Craft Cms
4.13.8 / 5.5.8+
CRITICAL 9.8
CVE-2024-56145 KEVEPSS 97%
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this…
Craft Cms
3.9.14 / 4.13.2+
HIGH 7.2
CVE-2024-52291
Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a doub…
Craft Cms
4.12.5 / 5.4.6+
MEDIUM 6.5
CVE-2024-52292
Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templat…
Craft Cms
4.12.8 / 5.4.9+
HIGH 7.2
CVE-2024-52293
Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could …
Craft Cms
4.12.2 / 5.4.3+
HIGH 7.5
CVE-2024-41800
Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to…
Craft Cms
5.2.3+
CRITICAL 9.8
CVE-2024-37843EPSS 53%
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
Craft Cms
3.7.31+
HIGH 7.5
CVE-2023-36260
An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings …
Craft Cms
4.6.1.1+
MEDIUM 5.4
CVE-2023-36259
Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creati…
Craft Cms
3.0.2+
HIGH 8.8
CVE-2024-21622
Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x…
Craft Cms
3.9.6+
CRITICAL 9.8
CVE-2023-41892EPSS 93%
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations befo…
Craft Cms
4.4.15+
HIGH 7.2
CVE-2023-40035
Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code e…
Craft Cms
3.8.15 / 4.4.15+
MEDIUM 6.1
CVE-2023-33495
Craft CMS through 4.4.9 is vulnerable to HTML Injection.
Craft Cms
after 4.4.9
HIGH 7.2
CVE-2023-30179
CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Loca…
Craft Cms
Patch available
MEDIUM 6.1
CVE-2023-33195
Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This issue was patched in version…
Craft Cms
4.4.6+
MEDIUM 5.4
CVE-2023-33196
Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in v…
Craft Cms
4.4.7+
MEDIUM 5.4
CVE-2023-33197
Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. Th…
Craft Cms
4.4.6+
MEDIUM 5.4
CVE-2023-2817
A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected i…
Craft Cms
after 4.4.11