Vulnerabilities in CraftCMS

147 results
Vexday analysis

CraftCMS apresenta 1 vulnerabilidade crítica catalogada (CVSS ≥ 9.0) associada a desserialização insegura (CWE-502), porém sem registros de exploração ativa em campo. A ausência de divulgações recentes sugere que a vulnerabilidade é conhecida e potencialmente já mitigada, reduzindo o risco imediato para ambientes atualizados.

CVE-2026-56384MEDIUMCraft CMS - Missing Authorization in assets/preview-thumb EndpointEPSS 0.3%CVE-2026-72786HIGHCraft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password ResetEPSS 0.3%CVE-2026-28781HIGHCraft Affected by Entries Authorship Spoofing via Mass AssignmentEPSS 0.3%CVE-2026-25491LOWCraft has a Stored XSS in Entry Types NameEPSS 0.3%CVE-2026-56393MEDIUMCraft CMS - Multiple Stored Cross-Site Scripting in Settings Names and Field OptionsEPSS 0.3%CVE-2026-29173LOWCraft Commerce has Stored XSS while updating Order Status from Orders TableEPSS 0.3%CVE-2026-25482MEDIUMCraft Commerce has Stored DOM XSS in Order Status Name (Reflects in "Recent Orders" Dashboard Widget)EPSS 0.3%CVE-2026-79989HIGHArbitrary user password reset leading to administrator account takeoverEPSS 0.3%CVE-2026-25483MEDIUMCraft Commerce has Stored XSS via Order Status Message with potential database exfiltrationEPSS 0.3%CVE-2026-56383MEDIUMCraft CMS - Stored XSS in Table Field via Row Heading Column TypeEPSS 0.3%CVE-2026-33159MEDIUMCraft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted usersEPSS 0.3%CVE-2026-32272HIGHCraft Commerce: Blind SQL Injection via hasVariant/hasProductEPSS 0.3%CVE-2026-55795MEDIUMCraft Commerce: Coupon Code Brute-Force via Rate Limit BypassEPSS 0.3%CVE-2026-32270LOWCraft Commerce: Unauthenticated information disclosure in `commerce/payments/pay` can leak some customer order data on anonymous paymentsEPSS 0.3%CVE-2026-25489MEDIUMCraft Commerce has Stored XSS in Tax Zones (Name & Description) Leading to Potential Privilege EscalationEPSS 0.3%CVE-2026-79991HIGHAuthenticated SQL Injection via nested eager-loading criteriaEPSS 0.3%CVE-2026-32262MEDIUMCraft CMS has a Path Traversal Vulnerability in AssetsControllerEPSS 0.3%CVE-2026-33162MEDIUMCraft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section permissionsEPSS 0.3%CVE-2026-84795CRITICALCraft CMS before 5.10.11 Authentication Bypass via Admin Flag InheritanceEPSS 0.3%CVE-2026-31867MEDIUMCraft Commerce has a Potential IDOR in Commerce cartsEPSS 0.3%