VendorsCraft CMScraft_cmsall versions
Vulnerabilities

Craft CMS craftcms Craft CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

97CVEs
CVE-2022-37246
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
Published 2022-09-21 · Modified
5.4EPSS 0.005
CVE-2022-37251
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.
Published 2022-09-16 · Modified
5.4EPSS 0.005
CVE-2023-2817
A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively.
Published 2023-05-26 · Modified
5.4EPSS 0.004
CVE-2023-36259
Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation.
Published 2024-01-30 · Modified
5.4EPSS 0.004
CVE-2026-33051
Craft CMS Vulnerable to Stored XSS in Revision Context Menu
Published 2026-03-20 · Analyzed
5.4EPSS 0.002
CVE-2019-14280
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public.
Published 2019-07-26 · Modified
5.31 PoCEPSS 0.094
CVE-2017-8383
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
Published 2017-05-01 · Modified
5.3EPSS 0.012
CVE-2017-8385
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
Published 2017-05-01 · Modified
5.3EPSS 0.010
CVE-2026-33160
Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform URL
Published 2026-03-24 · Analyzed
5.3EPSS 0.004
CVE-2026-32262
Craft CMS has a Path Traversal Vulnerability in AssetsController
Published 2026-03-16 · Analyzed
5.3EPSS 0.003
CVE-2026-28782
Craft has a Permission Bypass and IDOR in Duplicate Entry Action
Published 2026-03-04 · Analyzed
5.3EPSS 0.002
CVE-2018-20418
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
Published 2018-12-24 · Modified
4.81 PoCEPSS 0.037
CVE-2023-33194
CraftCMS stored XSS in Quick Post widget error message
Published 2023-05-26 · Modified
4.8EPSS 0.006
CVE-2026-25496
Craft has a stored XSS in Number Prefix & Suffix Fields
Published 2026-02-09 · Analyzed
4.8EPSS 0.004
CVE-2026-25491
Craft has a Stored XSS in Entry Types Name
Published 2026-02-09 · Analyzed
4.8EPSS 0.003
CVE-2026-33161
Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users
Published 2026-03-24 · Analyzed
4.3EPSS 0.002
CVE-2026-29113
Craft has a potential information disclosure vulnerability in preview tokens
Published 2026-03-10 · Modified
4.3EPSS 0.002
← Prev3 / 3