Vulnerability index

Browse CVEs

91 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2023-32679 Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension may lead to Remote Code Execu… Craft Cms 4.4.6+ Fix from $1,9502023-05-19 HIGH 8.8 CVE-2023-30130 An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter. Craft Cms No fix yet Fix from $1,9502023-05-12 MEDIUM 6.1 CVE-2023-31144 Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can d… Craft Cms after 4.4.3 Fix from $1,6002023-05-09 MEDIUM 6.1 CVE-2023-30177 CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name. Craft Cms Patch available Fix from $1,6002023-04-25 MEDIUM 5.4 CVE-2023-23927 Craft is a platform for creating digital experiences. When you insert a payload inside a label name or instruction of an entry type, an cross-site sc… Craft Cms 4.3.7+ Fix from $1,6002023-03-03 HIGH 7.5 CVE-2022-37783 All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSR… Craft Cms after 3.7.32 Fix from $1,9502022-12-05 MEDIUM 5.4 CVE-2022-37246 Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the lin… Craft Cms Patch available Fix from $1,6002022-09-21 MEDIUM 5.4 CVE-2022-37251 Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts. Craft Cms Mitigation only Fix from $1,6002022-09-16 MEDIUM 5.4 CVE-2022-37247 Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page. Craft Cms Patch available Fix from $1,6002022-09-16 MEDIUM 5.4 CVE-2022-37248 Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php. Craft Cms Patch available Fix from $1,6002022-09-16 MEDIUM 5.4 CVE-2022-37250 Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount. Craft Cms Patch available Fix from $1,6002022-09-16 HIGH 8.8 CVE-2022-29933 Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take ov… Craft Cms after 3.7.36 Fix from $1,9502022-05-09 MEDIUM 6.1 CVE-2022-28378 Craft CMS before 3.7.29 allows XSS. Craft Cms 3.7.29+ Fix from $1,6002022-04-03 HIGH 8.8 CVE-2021-41824 Craft CMS before 3.7.14 allows CSV injection. Craft Cms 3.7.14+ Fix from $1,9502021-09-30 CRITICAL 9.8 CVE-2021-27903 An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did n… Craft Cms 3.6.7+ Fix from $2,3002021-06-30 MEDIUM 6.1 CVE-2021-27902 An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms th… Craft Cms 3.6.0+ Fix from $1,6002021-06-30 MEDIUM 6.1 CVE-2021-32470 Craft CMS before 3.6.13 has an XSS vulnerability. Craft Cms 3.6.13+ Fix from $1,6002021-05-07 MEDIUM 5.4 CVE-2020-19626 Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/site… Craft Cms Patch available Fix from $1,6002021-03-26 CRITICAL 9.8 CVE-2020-9757EPSS 73% The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers co… Craft Cms 3.3.0+ Fix from $2,3002020-03-04 MEDIUM 6.1 CVE-2019-9554 In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new … Craft Cms No fix yet Fix from $1,6002019-12-31 CRITICAL 9.8 CVE-2019-15929 In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a … Craft Cms after 3.1.7 Fix from $2,3002019-10-24 MEDIUM 6.1 CVE-2019-17496 Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion. Craft Cms 3.3.8+ Fix from $1,6002019-10-11 MEDIUM 5.3 CVE-2019-14280EPSS 9% In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so,… Craft Cms 2.7.10 / 3.2.6+ Fix from $1,6002019-07-26 MEDIUM 6.1 CVE-2019-12823 Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS. Craft Cms 3.1.31+ Fix from $1,6002019-06-18 HIGH 7.2 CVE-2018-20465 Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated… Craft Cms after 3.0.34 Fix from $1,9502018-12-25 HIGH 8.8 CVE-2018-3814 Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option,… Craft Cms No fix yet Fix from $1,9502018-01-01 MEDIUM 5.4 CVE-2017-9516 Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file. Craft Cms after 2.6.2981 Fix from $1,6002017-06-08 MEDIUM 6.1 CVE-2017-8384 Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-… Craft Cms after 2.6.2974 Fix from $1,6002017-05-01 MEDIUM 5.3 CVE-2017-8383 Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder. Craft Cms after 2.6.2974 Fix from $1,6002017-05-01 MEDIUM 5.3 CVE-2017-8385 Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message. Craft Cms after 2.6.2974 Fix from $1,6002017-05-01