VendorsCraft CMScraft_cmsany version
Vulnerabilities

Craft CMS craftcms Craft CMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

85CVEs
CVE-2026-28781
Craft Affected by Entries Authorship Spoofing via Mass Assignment
Published 2026-03-04 · Analyzed
7.1EPSS 0.003
CVE-2026-27127
Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding
Published 2026-02-24 · Analyzed
7.0EPSS 0.005
CVE-2025-35939
Craft CMS stores user-provided content in session files
Published 2025-05-07 · Analyzed
6.9KEVEPSS 0.013
CVE-2026-25493
Craft has a SSRF in GraphQL Asset Mutation via HTTP Redirect
Published 2026-02-09 · Analyzed
6.9EPSS 0.004
CVE-2026-25494
Craft has a SSRF in GraphQL Asset Mutation via Alternative IP Notation
Published 2026-02-09 · Analyzed
6.9EPSS 0.004
CVE-2026-33159
Craft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted users
Published 2026-03-24 · Analyzed
6.9EPSS 0.003
CVE-2026-29069
Craft has an unauthenticated activation email trigger with potential user enumeration
Published 2026-03-04 · Analyzed
6.9EPSS 0.003
CVE-2026-31859
Craft has Reflective XSS via incomplete return URL sanitization
Published 2026-03-11 · Analyzed
6.9EPSS 0.002
CVE-2026-27128
Craft CMS's race condition in Token Service potentially allows for token usage greater than the token limit
Published 2026-02-24 · Analyzed
6.9EPSS 0.002
CVE-2025-68437
Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation
Published 2026-01-05 · Analyzed
6.8EPSS 0.005
CVE-2026-25492
Craft has a save_images_Asset graphql mutation can be abused to exfiltrate AWS credentials of underlying host
Published 2026-02-09 · Analyzed
6.5EPSS 0.004
CVE-2026-27129
Cloud Metadata SSRF Protection Bypass via IPv6 Resolution
Published 2026-02-24 · Analyzed
6.5EPSS 0.004
CVE-2026-33158
Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)
Published 2026-03-24 · Analyzed
6.5EPSS 0.004
CVE-2026-33162
Craft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section permissions
Published 2026-03-24 · Analyzed
6.5EPSS 0.003
CVE-2025-68436
Craft CMS vulnerable to potential information disclosure via unchecked asset relocation
Published 2026-01-05 · Analyzed
6.5EPSS 0.003
CVE-2021-27902
An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.
Published 2021-06-30 · Modified
6.1EPSS 0.010
CVE-2019-12823
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
Published 2019-06-18 · Modified
6.1EPSS 0.009
CVE-2019-17496
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
Published 2019-10-10 · Modified
6.1EPSS 0.008
CVE-2017-8384
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
Published 2017-05-01 · Modified
6.1EPSS 0.008
CVE-2017-8052
Craft CMS before 2.6.2974 allows XSS attacks.
Published 2017-04-22 · Modified
6.1EPSS 0.008
CVE-2023-23927
Craft CMS stored cross-site scripting vulnerability
Published 2023-03-03 · Modified
6.1EPSS 0.008
CVE-2021-32470
Craft CMS before 3.6.13 has an XSS vulnerability.
Published 2021-05-07 · Modified
6.1EPSS 0.007
CVE-2023-33195
Craft CMS XSS in RSS widget feed
Published 2023-05-27 · Modified
6.1EPSS 0.007
CVE-2022-28378
Craft CMS before 3.7.29 allows XSS.
Published 2022-04-03 · Modified
6.1EPSS 0.006
CVE-2023-33495
Craft CMS through 4.4.9 is vulnerable to HTML Injection.
Published 2023-06-20 · Modified
6.1EPSS 0.005
CVE-2023-31144
Craft CMS vulnerable to cross site scripting in RSS feed widget
Published 2023-05-09 · Modified
6.1EPSS 0.004
CVE-2026-27126
Craft CMS has Stored XSS in Table Field via "HTML" Column Type
Published 2026-02-24 · Analyzed
5.9EPSS 0.002
CVE-2023-33197
Craft CMS stored XSS in indexedVolumes
Published 2023-05-26 · Modified
5.5EPSS 0.007
CVE-2023-33196
Craft CMS stored XSS in review volume
Published 2023-05-26 · Modified
5.5EPSS 0.007
CVE-2024-45406
Craft CMS stored XSS in breadcrumb list and title fields
Published 2024-09-09 · Analyzed
5.5EPSS 0.004
CVE-2017-9516
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
Published 2017-06-08 · Modified
5.41 PoCEPSS 0.028
CVE-2023-2817
A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively.
Published 2023-05-26 · Modified
5.4EPSS 0.004
CVE-2023-36259
Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation.
Published 2024-01-30 · Modified
5.4EPSS 0.004
CVE-2026-33051
Craft CMS Vulnerable to Stored XSS in Revision Context Menu
Published 2026-03-20 · Analyzed
5.4EPSS 0.002
CVE-2019-14280
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
Published 2019-07-26 · Modified
5.31 PoCEPSS 0.094
CVE-2017-8383
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
Published 2017-05-01 · Modified
5.3EPSS 0.012
CVE-2017-8385
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
Published 2017-05-01 · Modified
5.3EPSS 0.010
CVE-2026-33160
Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform URL
Published 2026-03-24 · Analyzed
5.3EPSS 0.004
CVE-2026-32262
Craft CMS has a Path Traversal Vulnerability in AssetsController
Published 2026-03-16 · Analyzed
5.3EPSS 0.003
CVE-2026-28782
Craft has a Permission Bypass and IDOR in Duplicate Entry Action
Published 2026-03-04 · Analyzed
5.3EPSS 0.002
← Prev2 / 3Next →