Security Advisories for craftcms/cms in packagist
Critical
4 days ago
Craft CMS: Passkey login accepts replayed WebAuthn assertions
packagist
craftcms/cms
Moderate
5 days ago
Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
packagist
craftcms/cms
Moderate
5 days ago
Craft CMS: Authenticated leak of secret environment variables
packagist
craftcms/cms
Moderate
5 days ago
Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-element
packagist
craftcms/cms
Moderate
5 days ago
Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
packagist
craftcms/cms
Low
5 days ago
Craft CMS: Incorrect path validation could potentially lead to path traversal
packagist
craftcms/cms
Moderate
5 days ago
Craft CMS: Stored XSS in the control panel via unescaped draft name
packagist
craftcms/cms
High
5 days ago
Craft CMS: Arbitrary user password reset leading to administrator account takeover
packagist
craftcms/cms
Moderate
5 days ago
Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
packagist
craftcms/cms
High
5 days ago
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
packagist
craftcms/cms
High
about 1 month ago
Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
packagist
craftcms/cms
Low
about 1 month ago
Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read
packagist
craftcms/cms
High
about 1 month ago
Craft CMS: Potential authenticated Remote Code Execution via referrer redirect
packagist
craftcms/cms
Moderate
about 1 month ago
Craft CMS: Stored XSS via Structure entry title in table view
packagist
craftcms/cms
Moderate
about 1 month ago
Craft CMS: Sensitive File Disclosure / Server-Side File Read
packagist
craftcms/cms
High
about 1 month ago
Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget
packagist
craftcms/cms
Moderate
about 1 month ago
Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
packagist
craftcms/cms
High
about 1 month ago
Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
packagist
craftcms/cms
High
about 1 month ago
Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
packagist
craftcms/cms
High
about 1 month ago
Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets
packagist
craftcms/cms
Moderate
about 1 month ago
Craft CMS: Unauthorized Deletion of Source Assets During File Replacement
packagist
craftcms/cms
Moderate
about 1 month ago
Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check
packagist
craftcms/cms
High
about 1 month ago
Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap
packagist
craftcms/cms
Critical
about 2 months ago
Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
packagist
craftcms/cms
High
3 months ago
Craft CMS's Missing Volume Permission Check in AssetsController::actionShowInFolder Allows Information Disclosure
packagist
craftcms/cms
High
3 months ago
Craft CMS has Potential Authenticated Remote Code Execution via Malicious Attached Behavior
packagist
craftcms/cms
High
3 months ago
Craft CMS's Missing Authorization in GraphQL Address Resolver Allows Cross-Scope PII Disclosure
packagist
craftcms/cms
Moderate
4 months ago
Craft CMS has a host header injection leading to SSRF via resource-js endpoint
packagist
craftcms/cms
Moderate
4 months ago
Server-Side Request Forgery (SSRF) in Craft CMS with Asset Uploads Mutations
packagist
craftcms/cms
Moderate
4 months ago
Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action
packagist
craftcms/cms
Low
5 months ago
Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata
packagist
craftcms/cms
Moderate
5 months ago
Craft CMS has an authorization bypass which allows any control panel user to move entries without permissions
packagist
craftcms/cms
Low
5 months ago
Craft CMS' anonymous "assets/image-editor" calls return private asset editor metadata to unauthorized users
packagist
craftcms/cms
Low
5 months ago
Craft CMS may expose private assets through anonymous "generate transform" calls via transform URL
packagist
craftcms/cms
Moderate
5 months ago
Craft CMS: Unauthenticated Users Can Perform Restricted Project Config Sync Operations
packagist
craftcms/cms
Moderate
5 months ago
Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)
packagist
craftcms/cms
High
5 months ago
Craft CMS is Vulnerable to Authenticated Remote Code Execution via Malicious Attached Behavior
packagist
craftcms/cms
Moderate
5 months ago
Craft CMS Vulnerable to Stored XSS in Revision Context Menu
packagist
craftcms/cms
High
5 months ago
Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()
packagist
craftcms/cms
High
5 months ago
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
packagist
craftcms/cms
High
5 months ago
Craft CMS vulnerable to behavior injection RCE via EntryTypesController
packagist
craftcms/cms
Moderate
5 months ago
Craft CMS has a Path Traversal Vulnerability in AssetsController
packagist
craftcms/cms
Low
5 months ago
Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions Page
packagist
craftcms/cms
High
5 months ago
CraftCMS has an RCE vulnerability via relational conditionals in the control panel
packagist
craftcms/cms
High
5 months ago
CraftCMS's `ElementSearchController` Affected by Blind SQL Injection
packagist
craftcms/cms
Moderate
5 months ago
CraftCMS vulnerable to reflective XSS via incomplete return URL sanitization
packagist
craftcms/cms
Low
5 months ago
Craft CMS has a potential information disclosure vulnerability in preview tokens
packagist
craftcms/cms
High
5 months ago
Craft CMS has unauthenticated activation email trigger with potential user enumeration
packagist
craftcms/cms
Moderate
5 months ago
Craft CMS has potential authenticated Remote Code Execution via Twig SSTI
packagist
craftcms/cms
Moderate
5 months ago
Craft CMS has Permission Bypass and IDOR in Duplicate Entry Action
packagist
craftcms/cms
Moderate
5 months ago
Craft CMS: Entries Authorship Spoofing via Mass Assignment
packagist
craftcms/cms
Critical
5 months ago
Craft CMS Vulnerable to Authenticated RCE via "craft.app.fs.write()" in Twig Templates
packagist
craftcms/cms
Low
5 months ago
Craft CMS Vulnerable to Stored XSS in Settings Names and Field Options
packagist
craftcms/cms
Moderate
5 months ago
Craft CMS Vulnerable to Authenticated RCE via Twig SSTI - create() function + Symfony Process gadget
packagist
craftcms/cms
Low
6 months ago
Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type
packagist
craftcms/cms
Moderate
6 months ago
Craft CMS: Cloud Metadata SSRF Protection Bypass via IPv6 Resolution
packagist
craftcms/cms
Moderate
6 months ago
Craft CMS Race condition in Token Service potentially allows for token usage greater than the token limit
packagist
craftcms/cms
High
6 months ago
Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding
packagist
craftcms/cms
Moderate
6 months ago
Craft CMS has Stored XSS in Table Field via "HTML" Column Type
packagist
craftcms/cms
High
6 months ago
Craft CMS Vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
packagist
craftcms/cms
Moderate
6 months ago
Craft CMS Vulnerable to Stored XSS in Number Prefix & Suffix Fields
packagist
craftcms/cms
High
6 months ago
Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`
packagist
craftcms/cms
Moderate
6 months ago
Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via Alternative IP Notation
packagist
craftcms/cms
Moderate
6 months ago
Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via HTTP Redirect
packagist
craftcms/cms
High
7 months ago
Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
packagist
craftcms/cms
High
7 months ago
Unauthenticated Craft CMS users can trigger a database backup
packagist
craftcms/cms
Moderate
7 months ago
Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI
packagist
craftcms/cms
Moderate
7 months ago
Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation
packagist
craftcms/cms
Moderate
7 months ago
Craft CMS vulnerable to potential information disclosure via unchecked asset relocation
packagist
craftcms/cms
Moderate
12 months ago
Craft CMS Potential Remote Code Execution via Twig SSTI
packagist
craftcms/cms
Moderate
about 1 year ago
Craft CMS has a theoretical bypass for CVE-2025-23209
packagist
craftcms/cms
Moderate
over 1 year ago
Craft CMS stores arbitrary content provided by unauthenticated users in session files
packagist
craftcms/cms
High
over 1 year ago
Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI
packagist
craftcms/cms
High
over 1 year ago
Craft CMS has a potential RCE with a compromised security key
packagist
craftcms/cms
Critical
over 1 year ago
Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled
packagist
craftcms/cms
High
over 1 year ago
Craft CMS vulnerable to Potential Remote Code Execution via missing path normalization & Twig SSTI
packagist
craftcms/cms
High
over 1 year ago
Local File System Validation Bypass Leading to File Overwrite, Sensitive File Access, and Potential Code Execution
packagist
craftcms/cms
Moderate
almost 2 years ago
Craft CMS vulnerable to stored XSS in breadcrumb list and title fields
packagist
craftcms/cms
Moderate
about 2 years ago
Craft CMS Allows TOTP Token To Stay Valid After Use
packagist
craftcms/cms
Critical
about 2 years ago
Craft CMS SQL injection vulnerability via the GraphQL API endpoint
packagist
craftcms/cms
High
almost 3 years ago
Craft CMS vulnerable to Remote Code Execution via validatePath bypass
packagist
craftcms/cms
High
about 3 years ago
Craft CMS vulnerable to Remote Code Execution via unrestricted file extension
packagist
craftcms/cms
High
over 3 years ago
CraftCMS allows remote attacker to execute arbitrary code via crafted script to Section parameter
packagist
craftcms/cms
Moderate
over 3 years ago
craftcms/cms vulnerable to cross site scripting in RSS feed widget
packagist
craftcms/cms