VendorsCraft CMScraft_cmsany version
Vulnerabilities

Craft CMS craftcms Craft CMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

85CVEs
CVE-2023-33194
CraftCMS stored XSS in Quick Post widget error message
Published 2023-05-26 · Modified
4.8EPSS 0.006
CVE-2026-25496
Craft has a stored XSS in Number Prefix & Suffix Fields
Published 2026-02-09 · Analyzed
4.8EPSS 0.004
CVE-2026-25491
Craft has a Stored XSS in Entry Types Name
Published 2026-02-09 · Analyzed
4.8EPSS 0.003
CVE-2026-33161
Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users
Published 2026-03-24 · Analyzed
4.3EPSS 0.003
CVE-2026-29113
Craft has a potential information disclosure vulnerability in preview tokens
Published 2026-03-10 · Modified
4.3EPSS 0.002
← Prev3 / 3