Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.2
CVE-2023-32679
Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension may lead to Remote Code Execu…
Craft Cms
4.4.6+
HIGH 8.8
CVE-2023-30130
An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.
Craft Cms
No fix yet
MEDIUM 6.1
CVE-2023-31144
Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can d…
Craft Cms
after 4.4.3
MEDIUM 6.1
CVE-2023-30177
CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name.
Craft Cms
Patch available
MEDIUM 5.4
CVE-2023-23927
Craft is a platform for creating digital experiences. When you insert a payload inside a label name or instruction of an entry type, an cross-site sc…
Craft Cms
4.3.7+
HIGH 7.5
CVE-2022-37783
All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSR…
Craft Cms
after 3.7.32
MEDIUM 5.4
CVE-2022-37246
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the lin…
Craft Cms
Patch available
MEDIUM 5.4
CVE-2022-37251
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.
Craft Cms
Mitigation only
MEDIUM 5.4
CVE-2022-37247
Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.
Craft Cms
Patch available
MEDIUM 5.4
CVE-2022-37248
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.
Craft Cms
Patch available
MEDIUM 5.4
CVE-2022-37250
Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.
Craft Cms
Patch available
HIGH 8.8
CVE-2022-29933
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take ov…
Craft Cms
after 3.7.36
MEDIUM 6.1
CVE-2022-28378
Craft CMS before 3.7.29 allows XSS.
Craft Cms
3.7.29+
HIGH 8.8
CVE-2021-41824
Craft CMS before 3.7.14 allows CSV injection.
Craft Cms
3.7.14+
CRITICAL 9.8
CVE-2021-27903
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did n…
Craft Cms
3.6.7+
MEDIUM 6.1
CVE-2021-27902
An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms th…
Craft Cms
3.6.0+
MEDIUM 6.1
CVE-2021-32470
Craft CMS before 3.6.13 has an XSS vulnerability.
Craft Cms
3.6.13+
MEDIUM 5.4
CVE-2020-19626
Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/site…
Craft Cms
Patch available
CRITICAL 9.8
CVE-2020-9757EPSS 73%
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers co…
Craft Cms
3.3.0+
MEDIUM 6.1
CVE-2019-9554
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new …
Craft Cms
No fix yet
CRITICAL 9.8
CVE-2019-15929
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a …
Craft Cms
after 3.1.7
MEDIUM 6.1
CVE-2019-17496
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
Craft Cms
3.3.8+
MEDIUM 5.3
CVE-2019-14280EPSS 9%
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so,…
Craft Cms
2.7.10 / 3.2.6+
MEDIUM 6.1
CVE-2019-12823
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
Craft Cms
3.1.31+
HIGH 7.2
CVE-2018-20465
Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated…
Craft Cms
after 3.0.34
HIGH 8.8
CVE-2018-3814
Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option,…
Craft Cms
No fix yet
MEDIUM 5.4
CVE-2017-9516
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
Craft Cms
after 2.6.2981
MEDIUM 6.1
CVE-2017-8384
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-…
Craft Cms
after 2.6.2974
MEDIUM 5.3
CVE-2017-8383
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
Craft Cms
after 2.6.2974
MEDIUM 5.3
CVE-2017-8385
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
Craft Cms
after 2.6.2974