VendorsCraft CMScraft_cms5.0.0
Vulnerabilities

Craft CMS craftcms Craft CMS 5.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

38CVEs
CVE-2026-32267
Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()
Published 2026-03-16 · Analyzed
9.8EPSS 0.077
CVE-2026-28697
Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates
Published 2026-03-04 · Analyzed
9.4EPSS 0.011
CVE-2026-28783
Craft has a Twig Function Blocklist Bypass
Published 2026-03-04 · Analyzed
9.4EPSS 0.005
CVE-2025-68456
Unauthenticated Craft CMS users can trigger a database backup
Published 2026-01-05 · Analyzed
9.1EPSS 0.005
CVE-2025-68454
Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI
Published 2026-01-05 · Analyzed
8.8EPSS 0.009
CVE-2026-31857
CraftCMS has an RCE vulnerability via relational conditionals in the control panel
Published 2026-03-11 · Analyzed
8.8EPSS 0.007
CVE-2026-25495
Craft has a SQL Injection in Element Indexes via criteria[orderBy]
Published 2026-02-09 · Analyzed
8.8EPSS 0.005
CVE-2026-25497
Craft has a GraphQL Asset Mutation Privilege Escalation
Published 2026-02-09 · Analyzed
8.8EPSS 0.004
CVE-2026-31858
CraftCMS's `ElementSearchController` Affected by Blind SQL Injection
Published 2026-03-11 · Analyzed
8.8EPSS 0.004
CVE-2026-28696
Craft affected by IDOR via GraphQL @parseRefs
Published 2026-03-04 · Analyzed
8.7EPSS 0.004
CVE-2026-25498
Craft has a potential authenticated Remote Code Execution via malicious attached Behavior
Published 2026-02-09 · Analyzed
8.6EPSS 0.010
CVE-2025-68455
Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
Published 2026-01-05 · Analyzed
8.6EPSS 0.009
CVE-2026-28784
Craft is affected by potential authenticated Remote Code Execution via Twig SSTI
Published 2026-03-04 · Analyzed
8.6EPSS 0.005
CVE-2026-32264
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
Published 2026-03-16 · Analyzed
8.6EPSS 0.005
CVE-2024-52291
Craft has a Local File System Validation Bypass Leading to File Overwrite, Sensitive File Access, and Potential Code Execution
Published 2024-11-13 · Analyzed
8.4EPSS 0.012
CVE-2025-23209
Potential RCE with a compromised security key in craft/cms
Published 2025-01-18 · Analyzed
8.1KEVEPSS 0.218
CVE-2026-28695
Craft affected by authenticated RCE via Twig SSTI - create() function + Symfony Process gadget
Published 2026-03-04 · Analyzed
7.5EPSS 0.006
CVE-2024-41800
Craft CMS Allows TOTP Token To Stay Valid After Use
Published 2024-07-25 · Modified
7.5EPSS 0.005
CVE-2025-46731
Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI
Published 2025-05-05 · Analyzed
7.3EPSS 0.014
CVE-2024-52293
Craft has a Potential Remote Code Execution via missing path normalization & Twig SSTI
Published 2024-11-13 · Analyzed
7.2EPSS 0.014
CVE-2025-57811
Craft Potential Remote Code Execution via Twig SSTI
Published 2025-08-25 · Analyzed
7.2EPSS 0.009
CVE-2026-28781
Craft Affected by Entries Authorship Spoofing via Mass Assignment
Published 2026-03-04 · Analyzed
7.1EPSS 0.003
CVE-2026-27127
Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding
Published 2026-02-24 · Analyzed
7.0EPSS 0.005
CVE-2026-25494
Craft has a SSRF in GraphQL Asset Mutation via Alternative IP Notation
Published 2026-02-09 · Analyzed
6.9EPSS 0.004
CVE-2026-25493
Craft has a SSRF in GraphQL Asset Mutation via HTTP Redirect
Published 2026-02-09 · Analyzed
6.9EPSS 0.004
CVE-2026-33159
Craft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted users
Published 2026-03-24 · Analyzed
6.9EPSS 0.003
CVE-2026-29069
Craft has an unauthenticated activation email trigger with potential user enumeration
Published 2026-03-04 · Analyzed
6.9EPSS 0.003
CVE-2026-27128
Craft CMS's race condition in Token Service potentially allows for token usage greater than the token limit
Published 2026-02-24 · Analyzed
6.9EPSS 0.002
CVE-2025-68437
Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation
Published 2026-01-05 · Analyzed
6.8EPSS 0.005
CVE-2026-27129
Cloud Metadata SSRF Protection Bypass via IPv6 Resolution
Published 2026-02-24 · Analyzed
6.5EPSS 0.004
CVE-2026-33158
Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)
Published 2026-03-24 · Analyzed
6.5EPSS 0.004
CVE-2025-68436
Craft CMS vulnerable to potential information disclosure via unchecked asset relocation
Published 2026-01-05 · Analyzed
6.5EPSS 0.003
CVE-2026-27126
Craft CMS has Stored XSS in Table Field via "HTML" Column Type
Published 2026-02-24 · Analyzed
5.9EPSS 0.002
CVE-2026-33160
Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform URL
Published 2026-03-24 · Analyzed
5.3EPSS 0.004
CVE-2026-32262
Craft CMS has a Path Traversal Vulnerability in AssetsController
Published 2026-03-16 · Analyzed
5.3EPSS 0.003
CVE-2026-28782
Craft has a Permission Bypass and IDOR in Duplicate Entry Action
Published 2026-03-04 · Analyzed
5.3EPSS 0.002
CVE-2026-25496
Craft has a stored XSS in Number Prefix & Suffix Fields
Published 2026-02-09 · Analyzed
4.8EPSS 0.004
CVE-2026-33161
Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users
Published 2026-03-24 · Analyzed
4.3EPSS 0.002