VendorsCraft CMScraft_cmsany version
Vulnerabilities

Craft CMS craftcms Craft CMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

85CVEs
CVE-2025-32432
Craft CMS Allows Remote Code Execution
Published 2025-04-25 · Analyzed
10.0KEV1 PoCEPSS 0.998
CVE-2023-41892
Craft CMS Remote Code Execution vulnerability
Published 2023-09-13 · Modified
10.0EPSS 0.942
CVE-2024-56145
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
Published 2024-12-18 · Analyzed
9.8KEVEPSS 0.974
CVE-2020-9757
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.
Published 2020-03-04 · Modified
9.8EPSS 0.728
CVE-2024-37843
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
Published 2024-06-25 · Modified
9.8EPSS 0.532
CVE-2026-32267
Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()
Published 2026-03-16 · Analyzed
9.8EPSS 0.077
CVE-2021-27903
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).
Published 2021-06-30 · Modified
9.8EPSS 0.028
CVE-2019-15929
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
Published 2019-10-24 · Modified
9.8EPSS 0.018
CVE-2026-28697
Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates
Published 2026-03-04 · Analyzed
9.4EPSS 0.011
CVE-2026-28783
Craft has a Twig Function Blocklist Bypass
Published 2026-03-04 · Analyzed
9.4EPSS 0.005
CVE-2025-68456
Unauthenticated Craft CMS users can trigger a database backup
Published 2026-01-05 · Analyzed
9.1EPSS 0.005
CVE-2022-29933
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the password reset functionality. Specifically, the attacker must send X-Forwarded-Host to the /index.php?p=admin/actions/users/send-password-reset-email URI. NOTE: the vendor's position is that a customer can already work around this by adjusting the configuration (i.e., by not using the default configuration).
Published 2022-05-09 · Modified
8.8EPSS 0.045
CVE-2021-41824
Craft CMS before 3.7.14 allows CSV injection.
Published 2021-09-29 · Modified
8.8EPSS 0.014
CVE-2025-68454
Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI
Published 2026-01-05 · Analyzed
8.8EPSS 0.009
CVE-2026-31857
CraftCMS has an RCE vulnerability via relational conditionals in the control panel
Published 2026-03-11 · Analyzed
8.8EPSS 0.007
CVE-2024-21622
Craft CMS Privilege Escalation
Published 2024-01-03 · Modified
8.8EPSS 0.006
CVE-2026-25495
Craft has a SQL Injection in Element Indexes via criteria[orderBy]
Published 2026-02-09 · Analyzed
8.8EPSS 0.005
CVE-2025-54417
Craft contains a theoretical bypass for CVE-2025-23209
Published 2025-08-09 · Analyzed
8.8EPSS 0.005
CVE-2026-25497
Craft has a GraphQL Asset Mutation Privilege Escalation
Published 2026-02-09 · Analyzed
8.8EPSS 0.004
CVE-2026-31858
CraftCMS's `ElementSearchController` Affected by Blind SQL Injection
Published 2026-03-11 · Analyzed
8.8EPSS 0.004
CVE-2026-28696
Craft affected by IDOR via GraphQL @parseRefs
Published 2026-03-04 · Analyzed
8.7EPSS 0.004
CVE-2026-33157
Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior
Published 2026-03-24 · Analyzed
8.6EPSS 0.010
CVE-2026-25498
Craft has a potential authenticated Remote Code Execution via malicious attached Behavior
Published 2026-02-09 · Analyzed
8.6EPSS 0.010
CVE-2025-68455
Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
Published 2026-01-05 · Analyzed
8.6EPSS 0.009
CVE-2026-28784
Craft is affected by potential authenticated Remote Code Execution via Twig SSTI
Published 2026-03-04 · Analyzed
8.6EPSS 0.005
CVE-2026-32264
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
Published 2026-03-16 · Analyzed
8.6EPSS 0.005
CVE-2026-32263
Craft CMS vulnerable to behavior injection RCE via EntryTypesController
Published 2026-03-16 · Analyzed
8.6EPSS 0.005
CVE-2024-52291
Craft has a Local File System Validation Bypass Leading to File Overwrite, Sensitive File Access, and Potential Code Execution
Published 2024-11-13 · Analyzed
8.4EPSS 0.012
CVE-2025-23209
Potential RCE with a compromised security key in craft/cms
Published 2025-01-18 · Analyzed
8.1KEVEPSS 0.218
CVE-2024-52292
Craft Allows Attackers to Read Arbitrary System Files
Published 2024-11-13 · Analyzed
7.7EPSS 0.007
CVE-2023-36260
An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings to Feed-Me Name and Feed-Me URL fields, due to saving a feed using an Asset element type with no volume selected. NOTE: this is not a report about code provided by the Craft CMS product; it is only a report about the Feed Me plugin. NOTE: a third-party report states that commit b5d6ede51848349bd91bc95fec288b6793f15e28 has "nothing to do with security."
Published 2024-01-30 · Modified
7.5EPSS 0.011
CVE-2022-37783
All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site Request Forgery attacks. The CRAFT_CSRF_TOKEN cookie discloses the password hash in without encoding it whereas the corresponding HTML hidden field discloses the users' password hash in a masked manner, which can be decoded by using public functions of the YII framework.
Published 2022-12-05 · Modified
7.5EPSS 0.010
CVE-2026-28695
Craft affected by authenticated RCE via Twig SSTI - create() function + Symfony Process gadget
Published 2026-03-04 · Analyzed
7.5EPSS 0.006
CVE-2024-41800
Craft CMS Allows TOTP Token To Stay Valid After Use
Published 2024-07-25 · Modified
7.5EPSS 0.005
CVE-2025-46731
Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI
Published 2025-05-05 · Analyzed
7.3EPSS 0.014
CVE-2023-40035
Craft CMS vulnerable to Remote Code Execution via validatePath bypass
Published 2023-08-23 · Modified
7.2EPSS 0.023
CVE-2023-32679
Remote Code Execution via unrestricted file extension in Craft CMS
Published 2023-05-19 · Modified
7.2EPSS 0.018
CVE-2018-20465
Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes a cleartext username and password to be displayed in a URI field.
Published 2018-12-25 · Modified
7.2EPSS 0.015
CVE-2024-52293
Craft has a Potential Remote Code Execution via missing path normalization & Twig SSTI
Published 2024-11-13 · Analyzed
7.2EPSS 0.014
CVE-2025-57811
Craft Potential Remote Code Execution via Twig SSTI
Published 2025-08-25 · Analyzed
7.2EPSS 0.009
1 / 3Next →