craftcms has 39 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 35 in the last 90 days against 2 in the 90 before. The busiest recent month was July 2026 with 13. The median CVSS is 7.2 (high), with 3 rated critical. 3% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-862 (7) and CWE-94 (6). Most affected products: craftcms/cms (26), cms (9), craft_cms (2).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 3% vs 1% corpus
- Median CVSS
- 7.2
- Publish → KEV
- —(1)
- Last 90 days
- 35 prev 2
Products
- craftcms/cms 26
- cms 9
- craft_cms 2
- commerce 1
- craftcms/commerce 1
Worst active — by depth score
CVE-2025-32432Critical· 10.0Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond100GHSA-wg23-69c2-gjc8CriticalCraft CMS: Passkey login accepts replayed WebAuthn assertions52CVE-2026-55791CriticalCraft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs52CVE-2026-92593High· 8.8Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a self-signing oracle…49CVE-2026-92592High· 8.8Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC signature is not bou…49
craftcms vulnerabilities
CVEs affecting craftcms, newest first. Open any entry for full detail, references, and exploit status.
39 CVEsRSS
CVE-2026-50282HighCraft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
CVE-2026-50279HighCraft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap
Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap
CVE-2026-50280MediumCraft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check
Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check
CVE-2026-50283MediumCraft CMS: Unauthorized Deletion of Source Assets During File Replacement
Craft CMS: Unauthorized Deletion of Source Assets During File Replacement
CVE-2026-50284HighCraft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets
Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets
CVE-2026-55791CriticalCraft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
GHSA-78vr-q6cf-c7p6MediumCraft Commerce: Partial Payment Amount Without Lower Bound Validation
Craft Commerce: Partial Payment Amount Without Lower Bound Validation
CVE-2026-29113Medium· 4.3Craft is a content management system (CMS)
Craft is a content management system (CMS). Prior to 4.17.3 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action …
CVE-2025-32432Critical· 10.0CISA KEVPoCCraft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to r…