VulnSea

craftcms has 39 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 35 in the last 90 days against 2 in the 90 before. The busiest recent month was July 2026 with 13. The median CVSS is 7.2 (high), with 3 rated critical. 3% have been exploited in the wild, in line with the corpus average. The dominant weakness classes are CWE-862 (7) and CWE-94 (6). Most affected products: craftcms/cms (26), cms (9), craft_cms (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
3% vs 1% corpus
Median CVSS
7.2
Publish → KEV
—(1)
Last 90 days
35 prev 2

Products

  • craftcms/cms 26
  • cms 9
  • craft_cms 2
  • commerce 1
  • craftcms/commerce 1
39
Total CVEs
3
Critical
1
CISA KEV
1
Exploited

craftcms vulnerabilities

CVEs affecting craftcms, newest first. Open any entry for full detail, references, and exploit status.

39 CVEsRSS

CVE-2026-50282High
2mo ago

Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves

Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves

▾ Twilightcraftcms · craftcms/cmsEPSS 0.35%via GHSA
CVE-2026-50279High
2mo ago

Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap

Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap

▾ Twilightcraftcms · craftcms/cmsEPSS 0.36%via GHSA
CVE-2026-50280Medium
2mo ago

Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check

Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check

▾ Sunlitcraftcms · craftcms/cmsEPSS 0.40%via GHSA
CVE-2026-50283Medium
2mo ago

Craft CMS: Unauthorized Deletion of Source Assets During File Replacement

Craft CMS: Unauthorized Deletion of Source Assets During File Replacement

▾ Sunlitcraftcms · craftcms/cmsEPSS 0.36%via GHSA
CVE-2026-50284High
2mo ago

Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets

Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets

▾ Twilightcraftcms · craftcms/cmsEPSS 0.39%via GHSA
CVE-2026-55791Critical
3mo ago

Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs

Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs

▾ Midnightcraftcms · craftcms/cmsEPSS 0.46%via GHSA
GHSA-78vr-q6cf-c7p6Medium
3mo ago

Craft Commerce: Partial Payment Amount Without Lower Bound Validation

Craft Commerce: Partial Payment Amount Without Lower Bound Validation

▾ Sunlitcraftcms · craftcms/commercevia GHSA
CVE-2026-29113Medium· 4.3
6mo ago

Craft is a content management system (CMS)

Craft is a content management system (CMS). Prior to 4.17.3 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action …

▾ Sunlitcraftcms · craft_cmsEPSS 0.18%via NVD
CVE-2025-32432Critical· 10.0CISA KEVPoC
1y ago

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to r…

▾ Hadalcraftcms · craft_cmsEPSS 100%via NVD
craftcms vulnerabilities (CVEs) — page 2 · VulnSea