VulnSea

craftcms/cms vulnerabilities

CVEs whose affected-version data names the craftcms/cms package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

26 CVEsRSS

CVE-2026-79987High· 8.8
1w ago

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

Twilightcraftcms · craftcms/cmsEPSS 0.36%via NVD
GHSA-wg23-69c2-gjc8Critical
1mo ago

Craft CMS: Passkey login accepts replayed WebAuthn assertions

Craft CMS: Passkey login accepts replayed WebAuthn assertions

Midnightcraftcms · craftcms/cmsvia GHSA
GHSA-xxpx-f366-4xpqMedium
1mo ago

Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element

Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element

Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-p8x7-9vfw-p7vcHigh
1mo ago

Craft CMS: Arbitrary user password reset leading to administrator account takeover

Craft CMS: Arbitrary user password reset leading to administrator account takeover

Twilightcraftcms · craftcms/cmsvia GHSA
GHSA-2rp4-x2j7-qmccMedium
1mo ago

Craft CMS: Stored XSS in the control panel via unescaped draft name

Craft CMS: Stored XSS in the control panel via unescaped draft name

Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-7hxc-f267-h5q7Low
1mo ago

Craft CMS: Incorrect path validation could potentially lead to path traversal

Craft CMS: Incorrect path validation could potentially lead to path traversal

Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-rvmm-v933-jgxqMedium
1mo ago

Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics

Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics

Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-596p-6jv8-775vMedium
1mo ago

Craft CMS: Authenticated leak of secret environment variables

Craft CMS: Authenticated leak of secret environment variables

Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-957r-qf9p-67xwMedium
1mo ago

Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts

Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts

Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-265m-7826-wjqmHigh
1mo ago

Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass

Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass

Twilightcraftcms · craftcms/cmsvia GHSA
CVE-2026-14793Medium· 4.3
1mo ago

Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets

Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets

Sunlitcraftcms · craftcms/cmsEPSS 0.39%via GHSA
GHSA-f5wm-88jv-g5hxHigh
1mo ago

Craft CMS: Authenticated RCE through Twig sandbox escape

Craft CMS: Authenticated RCE through Twig sandbox escape

Twilightcraftcms · craftcms/cmsvia GHSA
GHSA-c43v-4cr8-6mvpLow
2mo ago

Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read

Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read

Sunlitcraftcms · craftcms/cmsvia GHSA
GHSA-86vw-x4ww-x467High
2mo ago

Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview

Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview

Twilightcraftcms · craftcms/cmsvia GHSA
CVE-2026-55790High
2mo ago

Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget

Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget

Twilightcraftcms · craftcms/cmsEPSS 0.46%via GHSA
CVE-2026-55792Medium
2mo ago

Craft CMS: Sensitive File Disclosure / Server-Side File Read

Craft CMS: Sensitive File Disclosure / Server-Side File Read

Sunlitcraftcms · craftcms/cmsEPSS 0.40%via GHSA
CVE-2026-55793Medium
2mo ago

Craft CMS: Stored XSS via Structure entry title in table view

Craft CMS: Stored XSS via Structure entry title in table view

Sunlitcraftcms · craftcms/cmsEPSS 0.41%via GHSA
CVE-2026-55794High
2mo ago

Craft CMS: Potential authenticated Remote Code Execution via referrer redirect

Craft CMS: Potential authenticated Remote Code Execution via referrer redirect

Twilightcraftcms · craftcms/cmsEPSS 0.41%via GHSA
GHSA-x76w-8c62-48mgMedium
2mo ago

Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission

Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission

Sunlitcraftcms · craftcms/cmsvia GHSA
CVE-2026-50281High
2mo ago

Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements

Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements

Twilightcraftcms · craftcms/cmsEPSS 0.43%via GHSA
CVE-2026-50282High
2mo ago

Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves

Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves

Twilightcraftcms · craftcms/cmsEPSS 0.35%via GHSA
CVE-2026-50279High
2mo ago

Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap

Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap

Twilightcraftcms · craftcms/cmsEPSS 0.36%via GHSA
CVE-2026-50280Medium
2mo ago

Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check

Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check

Sunlitcraftcms · craftcms/cmsEPSS 0.40%via GHSA
CVE-2026-50283Medium
2mo ago

Craft CMS: Unauthorized Deletion of Source Assets During File Replacement

Craft CMS: Unauthorized Deletion of Source Assets During File Replacement

Sunlitcraftcms · craftcms/cmsEPSS 0.36%via GHSA
CVE-2026-50284High
2mo ago

Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets

Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets

Twilightcraftcms · craftcms/cmsEPSS 0.39%via GHSA
CVE-2026-55791Critical
3mo ago

Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs

Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs

Midnightcraftcms · craftcms/cmsEPSS 0.46%via GHSA
craftcms/cms vulnerabilities (CVEs) · VulnSea