VendorsCraft CMScraft_cmsall versions
Vulnerabilities

Craft CMS craftcms Craft CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

97CVEs
CVE-2018-20465
Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes a cleartext username and password to be displayed in a URI field.
Published 2018-12-25 · Modified
7.2EPSS 0.015
CVE-2024-52293
Craft has a Potential Remote Code Execution via missing path normalization & Twig SSTI
Published 2024-11-13 · Analyzed
7.2EPSS 0.014
CVE-2025-57811
Craft Potential Remote Code Execution via Twig SSTI
Published 2025-08-25 · Analyzed
7.2EPSS 0.009
CVE-2026-28781
Craft Affected by Entries Authorship Spoofing via Mass Assignment
Published 2026-03-04 · Analyzed
7.1EPSS 0.003
CVE-2026-27127
Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding
Published 2026-02-24 · Analyzed
7.0EPSS 0.005
CVE-2025-35939
Craft CMS stores user-provided content in session files
Published 2025-05-07 · Analyzed
6.9KEVEPSS 0.013
CVE-2026-25493
Craft has a SSRF in GraphQL Asset Mutation via HTTP Redirect
Published 2026-02-09 · Analyzed
6.9EPSS 0.004
CVE-2026-25494
Craft has a SSRF in GraphQL Asset Mutation via Alternative IP Notation
Published 2026-02-09 · Analyzed
6.9EPSS 0.004
CVE-2026-33159
Craft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted users
Published 2026-03-24 · Analyzed
6.9EPSS 0.003
CVE-2026-29069
Craft has an unauthenticated activation email trigger with potential user enumeration
Published 2026-03-04 · Analyzed
6.9EPSS 0.003
CVE-2026-31859
Craft has Reflective XSS via incomplete return URL sanitization
Published 2026-03-11 · Analyzed
6.9EPSS 0.002
CVE-2026-27128
Craft CMS's race condition in Token Service potentially allows for token usage greater than the token limit
Published 2026-02-24 · Analyzed
6.9EPSS 0.002
CVE-2025-68437
Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation
Published 2026-01-05 · Analyzed
6.8EPSS 0.005
CVE-2026-25492
Craft has a save_images_Asset graphql mutation can be abused to exfiltrate AWS credentials of underlying host
Published 2026-02-09 · Analyzed
6.5EPSS 0.004
CVE-2026-27129
Cloud Metadata SSRF Protection Bypass via IPv6 Resolution
Published 2026-02-24 · Analyzed
6.5EPSS 0.004
CVE-2026-33158
Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)
Published 2026-03-24 · Analyzed
6.5EPSS 0.004
CVE-2026-33162
Craft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section permissions
Published 2026-03-24 · Analyzed
6.5EPSS 0.003
CVE-2025-68436
Craft CMS vulnerable to potential information disclosure via unchecked asset relocation
Published 2026-01-05 · Analyzed
6.5EPSS 0.003
CVE-2019-9554
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI.
Published 2019-12-31 · Modified
6.11 PoCEPSS 0.037
CVE-2021-27902
An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.
Published 2021-06-30 · Modified
6.1EPSS 0.010
CVE-2019-12823
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
Published 2019-06-18 · Modified
6.1EPSS 0.009
CVE-2019-17496
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
Published 2019-10-10 · Modified
6.1EPSS 0.008
CVE-2017-8384
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
Published 2017-05-01 · Modified
6.1EPSS 0.008
CVE-2017-8052
Craft CMS before 2.6.2974 allows XSS attacks.
Published 2017-04-22 · Modified
6.1EPSS 0.008
CVE-2023-23927
Craft CMS stored cross-site scripting vulnerability
Published 2023-03-03 · Modified
6.1EPSS 0.008
CVE-2021-32470
Craft CMS before 3.6.13 has an XSS vulnerability.
Published 2021-05-07 · Modified
6.1EPSS 0.007
CVE-2023-33195
Craft CMS XSS in RSS widget feed
Published 2023-05-27 · Modified
6.1EPSS 0.007
CVE-2022-28378
Craft CMS before 3.7.29 allows XSS.
Published 2022-04-03 · Modified
6.1EPSS 0.006
CVE-2023-33495
Craft CMS through 4.4.9 is vulnerable to HTML Injection.
Published 2023-06-20 · Modified
6.1EPSS 0.005
CVE-2023-31144
Craft CMS vulnerable to cross site scripting in RSS feed widget
Published 2023-05-09 · Modified
6.1EPSS 0.004
CVE-2023-30177
CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name.
Published 2023-04-25 · Modified
6.1EPSS 0.004
CVE-2026-27126
Craft CMS has Stored XSS in Table Field via "HTML" Column Type
Published 2026-02-24 · Analyzed
5.9EPSS 0.002
CVE-2023-33197
Craft CMS stored XSS in indexedVolumes
Published 2023-05-26 · Modified
5.5EPSS 0.007
CVE-2023-33196
Craft CMS stored XSS in review volume
Published 2023-05-26 · Modified
5.5EPSS 0.007
CVE-2024-45406
Craft CMS stored XSS in breadcrumb list and title fields
Published 2024-09-09 · Analyzed
5.5EPSS 0.004
CVE-2017-9516
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
Published 2017-06-08 · Modified
5.41 PoCEPSS 0.028
CVE-2020-19626
Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new.
Published 2021-03-26 · Modified
5.4EPSS 0.008
CVE-2022-37250
Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.
Published 2022-09-16 · Modified
5.4EPSS 0.007
CVE-2022-37248
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.
Published 2022-09-16 · Modified
5.4EPSS 0.006
CVE-2022-37247
Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.
Published 2022-09-16 · Modified
5.4EPSS 0.006
← Prev2 / 3Next →