Vulnerabilities in craftcms

147 results
Vexday analysis

O Craft CMS acumula 98 CVEs catalogadas, com uma taxa de exploração ativa que está bem acima da média do catálogo CISA KEV — 6,8 vezes superior —, sinalizando que vulnerabilidades nessa plataforma atraem atenção de agentes maliciosos de forma desproporcional. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), embora o risco mais imediato esteja concentrado na CVE-2025-32432, atualmente em exploração ativa e com EPSS de 0,998, indicando probabilidade altíssima de exploração em ambiente real. O volume de 16 CVEs surgidas nos últimos 90 dias reforça um ritmo de descoberta acelerado, exigindo ciclos de atualização frequentes por parte das equipes responsáveis por instâncias em produção. A presença de 3 CVEs no KEV, 5 de severidade crítica e 3 com PoC pública torna a priorização de patches não apenas recomendável, mas urgente.

CVE-2026-31857HIGHCraftCMS has an RCE vulnerability via relational conditionals in the control panelEPSS 0.7%CVE-2023-33196MEDIUMCraft CMS stored XSS in review volumeEPSS 0.7%CVE-2023-33195MEDIUMCraft CMS XSS in RSS widget feedEPSS 0.7%CVE-2020-37071CRITICALCraftCMS 3 vCard Plugin 1.0.0 - Remote Code ExecutionEPSS 0.6%CVE-2023-33194LOWCraftCMS stored XSS in Quick Post widget error messageEPSS 0.6%CVE-2026-78416HIGHAuthenticated RCE via `condition.config` JSON cleanse bypassEPSS 0.6%CVE-2024-21622MEDIUMCraft CMS Privilege EscalationEPSS 0.6%CVE-2026-28695HIGHCraft affected by authenticated RCE via Twig SSTI - create() function + Symfony Process gadgetEPSS 0.6%CVE-2025-68456HIGHUnauthenticated Craft CMS users can trigger a database backupEPSS 0.5%CVE-2026-72781HIGHCraft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox EscapeEPSS 0.5%CVE-2026-28784HIGHCraft is affected by potential authenticated Remote Code Execution via Twig SSTIEPSS 0.5%CVE-2026-25495HIGHCraft has a SQL Injection in Element Indexes via criteria[orderBy]EPSS 0.5%CVE-2026-32264HIGHCraft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsControllerEPSS 0.5%CVE-2026-86732HIGHCraft CMS before 5.10.12 Remote Code Execution via element-indexEPSS 0.5%CVE-2026-92592HIGHCraft CMS before 4.18.6 Remote Code Execution via signed cookieEPSS 0.5%CVE-2025-54417MEDIUMCraft contains a theoretical bypass for CVE-2025-23209EPSS 0.5%CVE-2026-32263HIGHCraft CMS vulnerable to behavior injection RCE via EntryTypesControllerEPSS 0.5%CVE-2026-56394HIGHCraft CMS - Authenticated Path Traversal in assets/icon Extension ParameterEPSS 0.5%CVE-2025-68437MEDIUMCraft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload MutationEPSS 0.5%CVE-2026-32271HIGHCraft Commerce: SQL Injection can lead to Remote Code Execution via TotalRevenue WidgetEPSS 0.5%