Vulnerabilidades en CraftCMS
147 resultadosAnálisis Vexday
CraftCMS apresenta 1 vulnerabilidade crítica catalogada (CVSS ≥ 9.0) associada a desserialização insegura (CWE-502), porém sem registros de exploração ativa em campo. A ausência de divulgações recentes sugere que a vulnerabilidade é conhecida e potencialmente já mitigada, reduzindo o risco imediato para ambientes atualizados.
CVE-2026-25488MEDIUMCraft Commerce has Stored XSS in Tax Categories (Name & Description) Fields Leading to Potential Privilege EscalationEPSS 0.3%CVE-2026-25490MEDIUMCraft Commerce has Stored XSS in Inventory Location Address Leading to Potential Privilege EscalationEPSS 0.3%CVE-2026-25484MEDIUMCraft Commerce has Stored XSS in Product Type NameEPSS 0.3%CVE-2026-25522MEDIUMCraft Commerce has Stored XSS in Shipping Zone (Name & Description) Fields Leading to Potential Privilege EscalationEPSS 0.3%CVE-2026-25487MEDIUMCraft CMS has Stored XSS in Tax Rates Name Leading to Potential Privilege EscalationEPSS 0.3%CVE-2026-25485MEDIUMCraft Commerce has Stored XSS in Shipping Categories (Name & Description) Fields Leading to Potential Privilege EscalationEPSS 0.3%CVE-2026-41129MEDIUMCraft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads MutationsEPSS 0.3%CVE-2026-29069MEDIUMCraft has an unauthenticated activation email trigger with potential user enumerationEPSS 0.3%CVE-2025-68436MEDIUMCraft CMS vulnerable to potential information disclosure via unchecked asset relocationEPSS 0.3%CVE-2026-25486MEDIUMCraft Commerce has Stored XSS in Shipping Methods Name Field Leading to Potential Privilege EscalationEPSS 0.3%CVE-2026-84796HIGHCraft CMS 5.0.0-RC1 before 5.10.11 GraphQL Entry Mutation Site Scope BypassEPSS 0.3%CVE-2026-92594HIGHCraft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQLEPSS 0.3%CVE-2026-41130MEDIUMCraft CMS has a host header injection leading to SSRF via resource-js endpointEPSS 0.3%CVE-2026-79988HIGHAuthenticated RCE through Twig sandbox escapeEPSS 0.3%CVE-2026-79990HIGHGQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/deleteEPSS 0.3%CVE-2026-56381MEDIUMCraft CMS - Stored XSS via User Group Name in User Permissions PageEPSS 0.3%CVE-2026-41128MEDIUMCraft CMS has a Missing Authorization Check on User Group Removal via save-permissions ActionEPSS 0.2%CVE-2026-84801HIGHCraft CMS 5.0.0-RC1 before 5.10.11 Authentication Bypass via administrateUsersEPSS 0.2%CVE-2026-33051MEDIUMCraft CMS Vulnerable to Stored XSS in Revision Context MenuEPSS 0.2%CVE-2026-92591HIGHCraft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via InstallerEPSS 0.2%