Vulnerabilities in CraftCMS
147 resultsVexday analysis
CraftCMS apresenta 1 vulnerabilidade crítica catalogada (CVSS ≥ 9.0) associada a desserialização insegura (CWE-502), porém sem registros de exploração ativa em campo. A ausência de divulgações recentes sugere que a vulnerabilidade é conhecida e potencialmente já mitigada, reduzindo o risco imediato para ambientes atualizados.
CVE-2026-28782MEDIUMCraft has a Permission Bypass and IDOR in Duplicate Entry ActionEPSS 0.2%CVE-2026-29176MEDIUMCraft Commerce has Stored XSS in Inventory Location NameEPSS 0.2%CVE-2026-72782HIGHCraft CMS 5.0.0-RC1 before 5.10.6 Environment Variable LeakEPSS 0.2%CVE-2026-72780HIGHCraft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkeyEPSS 0.2%CVE-2026-72779HIGHCraft CMS 5.0.0-RC1 before 5.10.6 Arbitrary File Read via SplFileObjectEPSS 0.2%CVE-2026-27126MEDIUMCraft CMS has Stored XSS in Table Field via "HTML" Column TypeEPSS 0.2%CVE-2026-33161LOWCraft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized usersEPSS 0.2%CVE-2026-29177LOWCraft Commerce has Stored XSS in Craft Commerce Order Details SlideoutEPSS 0.2%CVE-2026-29175HIGHMultiple Stored XSS in Commerce Inventory Page Leading to Session HijackingEPSS 0.2%CVE-2026-84798HIGHCraft CMS before 5.10.11 Authorization Bypass via actionDeleteForSiteEPSS 0.2%CVE-2026-84794HIGHCraft CMS 5.0.0 through 5.10.10 Authorization Bypass via assets/move-assetEPSS 0.2%CVE-2026-84800HIGHCraft CMS 5.0.0-RC1 before 5.10.11 File Overwrite via assets/replace-fileEPSS 0.2%CVE-2026-72785CRITICALCraft CMS before 5.10.6 Authorization Bypass via structures/move-elementEPSS 0.2%CVE-2026-72787MEDIUMCraft CMS 5.0.0-RC1 before 5.10.8 Stored XSS via Draft NameEPSS 0.2%CVE-2026-31859MEDIUMCraft has Reflective XSS via incomplete return URL sanitizationEPSS 0.2%CVE-2026-86731HIGHCraft CMS 5.0.0-RC1 before 5.10.12 Permission Escalation via UsersControllerEPSS 0.2%CVE-2026-84792MEDIUMCraft CMS before 5.10.11 Broken Access Control via element-indexesEPSS 0.2%CVE-2026-27128MEDIUMCraft CMS's race condition in Token Service potentially allows for token usage greater than the token limitEPSS 0.2%CVE-2026-29113LOWCraft has a potential information disclosure vulnerability in preview tokensEPSS 0.2%CVE-2026-84797MEDIUMCraft CMS 5.0.0-RC1 before 5.10.11 Authorization Bypass via actionDuplicateEPSS 0.2%