craftcms/cms vulnerabilities
CVEs whose affected-version data names the craftcms/cms package (composer). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
26 CVEsRSS
CVE-2026-79987High· 8.8A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.
A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.
GHSA-wg23-69c2-gjc8CriticalCraft CMS: Passkey login accepts replayed WebAuthn assertions
Craft CMS: Passkey login accepts replayed WebAuthn assertions
GHSA-xxpx-f366-4xpqMediumCraft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element
Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element
GHSA-p8x7-9vfw-p7vcHighCraft CMS: Arbitrary user password reset leading to administrator account takeover
Craft CMS: Arbitrary user password reset leading to administrator account takeover
GHSA-2rp4-x2j7-qmccMediumCraft CMS: Stored XSS in the control panel via unescaped draft name
Craft CMS: Stored XSS in the control panel via unescaped draft name
GHSA-7hxc-f267-h5q7LowCraft CMS: Incorrect path validation could potentially lead to path traversal
Craft CMS: Incorrect path validation could potentially lead to path traversal
GHSA-rvmm-v933-jgxqMediumCraft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
GHSA-596p-6jv8-775vMediumCraft CMS: Authenticated leak of secret environment variables
Craft CMS: Authenticated leak of secret environment variables
GHSA-957r-qf9p-67xwMediumCraft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
GHSA-265m-7826-wjqmHighCraft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
CVE-2026-14793Medium· 4.3Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
GHSA-f5wm-88jv-g5hxHighCraft CMS: Authenticated RCE through Twig sandbox escape
Craft CMS: Authenticated RCE through Twig sandbox escape
GHSA-c43v-4cr8-6mvpLowCraft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read
Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read
GHSA-86vw-x4ww-x467HighCraft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
CVE-2026-55790HighCraft CMS: DOM XSS via GitHub issue title in CraftSupport widget
Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget
CVE-2026-55792MediumCraft CMS: Sensitive File Disclosure / Server-Side File Read
Craft CMS: Sensitive File Disclosure / Server-Side File Read
CVE-2026-55793MediumCraft CMS: Stored XSS via Structure entry title in table view
Craft CMS: Stored XSS via Structure entry title in table view
CVE-2026-55794HighCraft CMS: Potential authenticated Remote Code Execution via referrer redirect
Craft CMS: Potential authenticated Remote Code Execution via referrer redirect
GHSA-x76w-8c62-48mgMediumCraft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
CVE-2026-50281HighCraft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
CVE-2026-50282HighCraft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
CVE-2026-50279HighCraft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap
Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap
CVE-2026-50280MediumCraft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check
Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check
CVE-2026-50283MediumCraft CMS: Unauthorized Deletion of Source Assets During File Replacement
Craft CMS: Unauthorized Deletion of Source Assets During File Replacement
CVE-2026-50284HighCraft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets
Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets
CVE-2026-55791CriticalCraft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs