Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Craftercms CRITICAL 9.1
CVE-2025-6384

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS co…

Fix: 4.3.0+
Fix from $2,300 2025-06-19
Craftercms CRITICAL 9.1
CVE-2025-0502

Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS, x86, Windows, 64 bit, ARM a…

Fix: 4.0.8 / 4.1.6+
Fix from $2,300 2025-01-15
Craftercms MEDIUM 6.1
CVE-2023-4136

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86…

Fix: after 4.0.2
Fix from $1,600 2023-08-03
Crafter Cms HIGH 7.2
CVE-2023-26020

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crafter Studio on Linux, MacOS, Windows, x86, A…

Fix: after 4.0.1
Fix from $1,950 2023-02-17
Crafter Cms HIGH 7.2
CVE-2022-40634

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS c…

Fix: 3.1.23+
Fix from $1,950 2022-09-13
Crafter Cms HIGH 7.2
CVE-2022-40635

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS c…

Fix: 3.1.23+
Fix from $1,950 2022-09-13
Crafter Cms HIGH 8.8
CVE-2021-23267

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS c…

Fix: 3.1.18+
Fix from $1,950 2022-05-16
Crafter Cms CRITICAL 9.1
CVE-2021-23264

Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.

Fix: 3.1.15+
Fix from $2,300 2021-12-02
Crafter Cms HIGH 7.5
CVE-2021-23263

Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (n…

Fix: 3.1.15+
Fix from $1,950 2021-12-02
Crafter Cms HIGH 7.2
CVE-2021-23258

Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans. SPEL Expression does not have s…

Fix: 3.1.12+
Fix from $1,950 2021-12-02
Crafter Cms HIGH 7.2
CVE-2021-23259

Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The gro…

Fix: 3.1.12+
Fix from $1,950 2021-12-02
Crafter Cms HIGH 7.2
CVE-2021-23262

Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.

Fix: 3.1.13+
Fix from $1,950 2021-12-02
Crafter Cms MEDIUM 5.4
CVE-2021-23260

Authenticated users with Site roles may inject XSS scripts via file names that will execute in the browser for this and other users of the same site.

Fix: 3.1.12+
Fix from $1,600 2021-12-02
Crafter Cms HIGH 8.6
CVE-2017-15683

In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS f…

Fix: 3.0.1+
Fix from $1,950 2020-11-27
Crafter Cms HIGH 8.6
CVE-2017-15685

Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to create a site with specially craft…

Fix: 3.0.1+
Fix from $1,950 2020-11-27
Crafter Cms HIGH 7.5
CVE-2017-15684

Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view files from the operating syst…

Fix: 3.0.1+
Fix from $1,950 2020-11-27
Crafter Cms MEDIUM 6.1
CVE-2017-15682

In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to inject malicious JavaScript code resulting in a stored/blind XSS in the ad…

Fix: 3.0.1+
Fix from $1,600 2020-11-27
Crafter Cms MEDIUM 6.1
CVE-2017-15686

Crafter CMS Crafter Studio 3.0.1 is affected by: Cross Site Scripting (XSS), which allows remote attackers to steal users’ cookies.

Fix: 3.0.1+
Fix from $1,600 2020-11-27
Crafter Cms CRITICAL 9.8
CVE-2017-15681

In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the ope…

Fix: 3.0.1+
Fix from $2,300 2020-11-27
Crafter Cms MEDIUM 6.5
CVE-2017-15680

In Crafter CMS Crafter Studio 3.0.1 an IDOR vulnerability exists which allows unauthenticated attackers to view and modify administrative data.

Fix: 3.0.1+
Fix from $1,600 2020-11-27
Studio HIGH 7.2
CVE-2020-25803

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS c…

Fix: 3.0.27 / 3.1.7+
Fix from $1,950 2020-10-06
Studio HIGH 7.2
CVE-2020-25802

Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS c…

Fix: 3.0.27 / 3.1.7+
Fix from $1,950 2020-10-06
Crafter Cms HIGH 8.8
CVE-2018-19907

A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/…

Fix: after 3.0.18
Fix from $1,950 2018-12-06