CVE-2025-68436Medium· 6.5▾ SunlitCraft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.
craft_cms >= 4.0.0.1, < 4.16.17craft_cms >= 5.0.1, < 5.8.21craft_cms = 4.0.0craft_cms = 5.0.0Upgrade past the affected range:
craft_cms 5.8.21Connected by shared product, vendor, weakness, or advisory.
CVE-2025-68454High· 8.8Craft is a platform for creating digital experiences
CVE-2025-68455High· 7.2Craft is a platform for creating digital experiences
CVE-2025-68456Critical· 9.1Craft is a platform for creating digital experiences
CVE-2025-68437Medium· 6.8Craft is a platform for creating digital experiences
CVE-2025-32432Critical· 10.0Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond
CVE-2026-92594High· 7.5Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are…