VendorsCraft CMScraft_cms4.5.0
Vulnerabilities

Craft CMS craftcms Craft CMS 4.5.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2026-27128
Craft CMS's race condition in Token Service potentially allows for token usage greater than the token limit
Published 2026-02-24 · Analyzed
6.9EPSS 0.002
CVE-2026-27126
Craft CMS has Stored XSS in Table Field via "HTML" Column Type
Published 2026-02-24 · Analyzed
5.9EPSS 0.002