craftcms/cms
Packagist66 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting craftcms/cmspage 1 of 2
- CVE-2017-8052MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2.6.29742017-04-22
vulnerable: 1.0.26.1 ... 2.6.2973 (276 versions)
Craft CMS before 2.6.2974 allows XSS attacks.
- CVE-2017-8383MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.6.29762017-05-01
vulnerable: 1.0.26.1 ... 2.6.2975 (278 versions)
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder.
- CVE-2017-8384MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2.6.29762017-05-01
vulnerable: 1.0.26.1 ... 2.6.2975 (278 versions)
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-8052.
- CVE-2017-8385MEDIUMCVSS 5.3EG 5.3✓ Fixed in 2.6.29762017-05-01
vulnerable: 1.0.26.1 ... 2.6.2975 (278 versions)
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.
- CVE-2017-9516MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.6.29822017-06-08
vulnerable: 1.0.26.1 ... 2.6.2981 (284 versions)
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file.
- CVE-2018-20418MEDIUMCVSS 4.8EG 4.82018-12-24
vulnerable: 1.0.26.1 ... 3.0.9 (438 versions)
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
- CVE-2018-20465HIGHCVSS 7.2EG 7.22018-12-25
vulnerable: 1.0.26.1 ... 3.0.9 (451 versions)
Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI F…
- CVE-2018-3814HIGHCVSS 8.8EG 8.82018-01-01
vulnerable: 1.0.26.1 ... 2.6.3000 (303 versions)
Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option, because this allows a .jpg file to have embedded PHP code, and then be renamed to a .php …
- CVE-2019-12823MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.1.312019-06-18
vulnerable: 1.0.26.1 ... 3.1.9.1 (507 versions)
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS.
- CVE-2019-15929CRITICALCVSS 9.8EG 9.8✓ Fixed in 3.1.72019-10-24
vulnerable: 1.0.26.1 ... 3.1.6.1 (478 versions)
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
- CVE-2019-17496MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.3.82019-10-11
vulnerable: 1.0.26.1 ... 3.3.7 (558 versions)
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion.
- CVE-2020-19626MEDIUMCVSS 5.4EG 5.4✓ Fixed in 3.1.332021-03-26
vulnerable: 1.0.26.1 ... 3.1.9.1 (510 versions)
Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new.
- CVE-2021-27902MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.6.02021-06-30
vulnerable: 1.0.26.1 ... 3.6.0-beta.2 (676 versions)
An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.
- CVE-2021-27903CRITICALCVSS 9.8EG 9.8✓ Fixed in 3.6.72021-06-30
vulnerable: 1.0.26.1 ... 3.6.6 (686 versions)
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administ…
- CVE-2021-32470MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.6.132021-05-07
vulnerable: 1.0.26.1 ... 3.6.9 (695 versions)
Craft CMS before 3.6.13 has an XSS vulnerability.
- CVE-2021-41824HIGHCVSS 8.8EG 8.8✓ Fixed in 3.7.142021-09-30
vulnerable: 3.4.0 ... 3.7.9 (135 versions)
Craft CMS before 3.7.14 allows CSV injection.
- CVE-2022-28378MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.7.292022-04-03
vulnerable: 1.0.26.1 ... 3.7.9 (746 versions)
Craft CMS before 3.7.29 allows XSS.
- CVE-2022-29933HIGHCVSS 8.8EG 8.8✓ Fixed in 3.7.362022-05-09
vulnerable: 1.0.26.1 ... 3.7.9 (754 versions)
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the passw…
- CVE-2022-37246MEDIUMCVSS 5.4EG 5.4✓ Fixed in 3.7.512022-09-21
vulnerable: 3.7.39 ... 3.7.50 (16 versions)
Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.
- CVE-2022-37247MEDIUMCVSS 5.4EG 5.4✓ Fixed in 4.2.12022-09-16
vulnerable: 4.0.0 ... 4.2.0.2 (24 versions)
Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.
- CVE-2022-37248MEDIUMCVSS 5.4EG 5.4✓ Fixed in 4.2.12022-09-16
vulnerable: 4.0.0 ... 4.2.0.2 (24 versions)
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.
- CVE-2022-37250MEDIUMCVSS 5.4EG 5.4✓ Fixed in 4.2.12022-09-16
vulnerable: 4.0.0 ... 4.2.0.2 (24 versions)
Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.
- CVE-2022-37251MEDIUMCVSS 5.4EG 5.4✓ Fixed in 4.2.12022-09-16
vulnerable: 4.0.0 ... 4.2.0.2 (24 versions)
Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.
- CVE-2022-37783HIGHCVSS 7.5EG 7.5✓ Fixed in 3.7.332022-12-05
vulnerable: 3.0.0 ... 3.7.9 (350 versions)
All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called C…
- CVE-2023-23927MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.7.642023-03-03
vulnerable: 3.7.24 ... 3.7.63.1 (53 versions)
Craft is a platform for creating digital experiences. When you insert a payload inside a label name or instruction of an entry type, an cross-site scripting (XSS) happens in the quick post widget on the admin dashboard. This issue has been…
- CVE-2023-2817MEDIUMCVSS 5.4EG 5.4✓ Fixed in 4.4.122023-05-26
vulnerable: 4.0.0 ... 4.4.9 (74 versions)
A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when…
- CVE-2023-30130HIGHCVSS 8.8EG 8.82023-05-12
vulnerable: 1.0.26.1 ... 3.8.1 (807 versions)
An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.
- CVE-2023-30177MEDIUMCVSS 6.1EG 6.1✓ Fixed in 3.7.682023-04-25
vulnerable: 1.0.26.1 ... 3.7.9 (798 versions)
CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name.
- CVE-2023-31144MEDIUMCVSS 6.1EG 6.1✓ Fixed in 4.4.42023-05-09
vulnerable: 4.0.0 ... 4.4.3 (60 versions)
Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can deliver a cross-site scripting payload. This issue is fixed in version 3.8.4 and 4.4.4.
- CVE-2023-32679HIGHCVSS 7.2EG 7.2✓ Fixed in 4.4.62023-05-19
vulnerable: 4.0.0 ... 4.4.5 (62 versions)
Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension may lead to Remote Code Execution. If the name parameter value is not empty string('') in the View.php's doesTemplateEx…
- CVE-2023-33194LOWCVSS 3.7EG 3.7✓ Fixed in 3.8.62023-05-26
vulnerable: 3.0.0 ... 3.8.5 (410 versions)
Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn��…
- CVE-2023-33195MEDIUMCVSS 5.0EG 5.0✓ Fixed in 4.4.62023-05-27
vulnerable: 4.3.0 ... 4.4.5 (30 versions)
Craft is a CMS for creating custom digital experiences on the web. A malformed RSS feed can deliver an XSS payload. This issue was patched in version 4.4.6.
- CVE-2023-33196MEDIUMCVSS 5.5EG 5.5✓ Fixed in 4.4.72023-05-26
vulnerable: 4.0.0 ... 4.4.6.1 (67 versions)
Craft is a CMS for creating custom digital experiences. Cross site scripting (XSS) can be triggered by review volumes. This issue has been fixed in version 4.4.7.
- CVE-2023-33197MEDIUMCVSS 5.5EG 5.5✓ Fixed in 4.4.62023-05-26
vulnerable: 4.0.0 ... 4.4.5 (65 versions)
Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.
- CVE-2023-33495MEDIUMCVSS 6.1EG 6.12023-06-20
vulnerable: 1.0.26.1 ... 4.4.9 (909 versions)
Craft CMS through 4.4.9 is vulnerable to HTML Injection.
- CVE-2023-36260HIGHCVSS 7.5EG 7.5✓ Fixed in 4.6.22024-01-30
vulnerable: 1.0.26.1 ... 4.6.1 (942 versions)
An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings to Feed-Me Name and Feed-Me URL fields, due to saving a feed using an Asset element type w…
- CVE-2023-40035HIGHCVSS 7.2EG 7.2✓ Fixed in 3.8.152023-08-23
vulnerable: 3.0.0 ... 3.8.9 (421 versions)
Craft is a CMS for creating custom digital experiences on the web and beyond. Bypassing the validatePath function can lead to potential remote code execution. This vulnerability can lead to malicious control of vulnerable systems and data …
- CVE-2023-41892CRITICALCVSS 10.0EG 10.0✓ Fixed in 4.4.152023-09-13
vulnerable: 4.0.0 ... 4.4.9 (77 versions)
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This is…
- CVE-2024-21622MEDIUMCVSS 5.4EG 5.4✓ Fixed in 3.9.62024-01-03
vulnerable: 3.0.0 ... 3.9.5 (430 versions)
Craft is a content management system. This is a potential moderate impact, low complexity privilege escalation vulnerability in Craft starting in 3.x prior to 3.9.6 and 4.x prior to 4.4.16 with certain user permissions setups. This has bee…
- CVE-2024-37843CRITICALCVSS 9.8EG 9.82024-06-25
vulnerable: 1.0.26.1 ... 3.7.9 (750 versions)
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
- CVE-2024-41800MEDIUMCVSS 4.8EG 4.8✓ Fixed in 5.2.32024-07-25
vulnerable: 5.0.0 ... 5.2.2 (39 versions)
Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that th…
- CVE-2024-45406MEDIUMCVSS 5.5EG 5.5✓ Fixed in 5.1.22024-09-09
vulnerable: 5.0.0 ... 5.1.1 (9 versions)
Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.
- CVE-2024-52291HIGHCVSS 8.4EG 8.4✓ Fixed in 4.12.52024-11-13
vulnerable: 4.0.0 ... 4.9.7 (155 versions)
Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a double file:// scheme (e.g., file://file:////). This enables the attacker to specify sensitive…
- CVE-2024-52292HIGHCVSS 7.7EG 7.7✓ Fixed in 4.12.82024-11-13
vulnerable: 3.5.13 ... 4.9.7 (344 versions)
Craft is a content management system (CMS). The dataUrl function can be exploited if an attacker has write permissions on system notification templates. This function accepts an absolute file path, reads the file's content, and converts it…
- CVE-2024-52293HIGHCVSS 7.2EG 7.2✓ Fixed in 5.4.32024-11-13
vulnerable: 5.0.0 ... 5.4.2 (53 versions)
Craft is a content management system (CMS). Prior to 4.12.2 and 5.4.3, Craft is missing normalizePath in the function FileHelper::absolutePath could lead to Remote Code Execution on the server via twig SSTI. This is a sequel to CVE-2023-40…
- CVE-2024-56145CRITICALCVSS 9.8EG 9.8⚠ KEV✓ Fixed in 3.9.142024-12-18
vulnerable: 3.0.0 ... 3.9.6 (435 versions)
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these …
- CVE-2025-46731HIGHCVSS 7.2EG 7.2✓ Fixed in 4.14.132025-05-05
vulnerable: 4.0.0 ... 4.9.7 (190 versions)
Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access…
- CVE-2025-57811HIGHCVSS 7.2EG 7.2✓ Fixed in 4.16.62025-08-25
vulnerable: 4.0.0 ... 4.9.7 (213 versions)
Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig SSTI (Server-Side Template Injection). This is a follow-up to…
- CVE-2025-68437MEDIUMCVSS 6.8EG 6.8✓ Fixed in 5.8.212026-01-05
vulnerable: 5.0.0 ... 5.8.9 (142 versions)
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save_<VolumeName>_Asset` mutation is vulnerable to Server-Side Request Forgery (SSRF). This vu…
- CVE-2025-68454HIGHCVSS 8.8EG 8.8✓ Fixed in 5.8.212026-01-05
vulnerable: 5.0.0 ... 5.8.9 (142 versions)
Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via Twig SSTI. For this to work, users must have administ…
Check whether craftcms/cms is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for craftcms/cms CVEs against the assets you own.
Start Free Scan →