Vulnerabilidades en craftcms

147 resultados
Análisis Vexday

O Craft CMS acumula 98 CVEs catalogadas, com uma taxa de exploração ativa que está bem acima da média do catálogo CISA KEV — 6,8 vezes superior —, sinalizando que vulnerabilidades nessa plataforma atraem atenção de agentes maliciosos de forma desproporcional. O tipo de falha mais frequente é CWE-79 (Cross-Site Scripting), embora o risco mais imediato esteja concentrado na CVE-2025-32432, atualmente em exploração ativa e com EPSS de 0,998, indicando probabilidade altíssima de exploração em ambiente real. O volume de 16 CVEs surgidas nos últimos 90 dias reforça um ritmo de descoberta acelerado, exigindo ciclos de atualização frequentes por parte das equipes responsáveis por instâncias em produção. A presença de 3 CVEs no KEV, 5 de severidade crítica e 3 com PoC pública torna a priorização de patches não apenas recomendável, mas urgente.

CVE-2026-55791MEDIUMCraft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJsEPSS 0.5%CVE-2026-28783CRITICALCraft has a Twig Function Blocklist BypassEPSS 0.5%CVE-2026-55790HIGHCraft CMS: DOM XSS via GitHub issue title in CraftSupport widgetEPSS 0.5%CVE-2024-41800MEDIUMCraft CMS Allows TOTP Token To Stay Valid After UseEPSS 0.5%CVE-2026-72778HIGHCraft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.configEPSS 0.4%CVE-2026-28696HIGHCraft affected by IDOR via GraphQL @parseRefsEPSS 0.4%CVE-2026-27127HIGHCraft CMS has Cloud Metadata SSRF Protection Bypass via DNS RebindingEPSS 0.4%CVE-2026-25497HIGHCraft has a GraphQL Asset Mutation Privilege EscalationEPSS 0.4%CVE-2026-29174HIGHCraft Commerce has a SQL Injection in Commerce Inventory Table SortingEPSS 0.4%CVE-2026-25492MEDIUMCraft has a save_images_Asset graphql mutation can be abused to exfiltrate AWS credentials of underlying hostEPSS 0.4%CVE-2026-50281HIGHCraft CMS: Mass assignment via id in newAttributes during bulk duplicate overwrites existing elementsEPSS 0.4%CVE-2026-27129MEDIUMCloud Metadata SSRF Protection Bypass via IPv6 ResolutionEPSS 0.4%CVE-2026-29172HIGHCraft Commerce has a SQL Injection in Commerce Purchasables Table SortingEPSS 0.4%CVE-2026-92593HIGHCraft CMS 5.10.0 before 5.10.13 Authenticated Remote Code ExecutionEPSS 0.4%CVE-2026-55793MEDIUMCraft CMS: Stored XSS via Structure entry title in table viewEPSS 0.4%CVE-2026-55794HIGHCraft CMS: Potential authenticated Remote Code Execution via referrer redirectEPSS 0.4%CVE-2023-31144MEDIUMCraft CMS vulnerable to cross site scripting in RSS feed widgetEPSS 0.4%CVE-2026-50280MEDIUMCraft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save checkEPSS 0.4%CVE-2026-55792MEDIUMCraft CMS: Sensitive File Disclosure / Server-Side File ReadEPSS 0.4%CVE-2026-86730HIGHCraft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCEEPSS 0.4%