Vulnerabilidades em CraftCMS

147 resultados
Análise Vexday

CraftCMS apresenta 1 vulnerabilidade crítica catalogada (CVSS ≥ 9.0) associada a desserialização insegura (CWE-502), porém sem registros de exploração ativa em campo. A ausência de divulgações recentes sugere que a vulnerabilidade é conhecida e potencialmente já mitigada, reduzindo o risco imediato para ambientes atualizados.

CVE-2026-55791MEDIUMCraft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJsEPSS 0.5%CVE-2026-28783CRITICALCraft has a Twig Function Blocklist BypassEPSS 0.5%CVE-2026-55790HIGHCraft CMS: DOM XSS via GitHub issue title in CraftSupport widgetEPSS 0.5%CVE-2024-41800MEDIUMCraft CMS Allows TOTP Token To Stay Valid After UseEPSS 0.5%CVE-2026-72778HIGHCraft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.configEPSS 0.4%CVE-2026-28696HIGHCraft affected by IDOR via GraphQL @parseRefsEPSS 0.4%CVE-2026-27127HIGHCraft CMS has Cloud Metadata SSRF Protection Bypass via DNS RebindingEPSS 0.4%CVE-2026-25497HIGHCraft has a GraphQL Asset Mutation Privilege EscalationEPSS 0.4%CVE-2026-29174HIGHCraft Commerce has a SQL Injection in Commerce Inventory Table SortingEPSS 0.4%CVE-2026-25492MEDIUMCraft has a save_images_Asset graphql mutation can be abused to exfiltrate AWS credentials of underlying hostEPSS 0.4%CVE-2026-50281HIGHCraft CMS: Mass assignment via id in newAttributes during bulk duplicate overwrites existing elementsEPSS 0.4%CVE-2026-27129MEDIUMCloud Metadata SSRF Protection Bypass via IPv6 ResolutionEPSS 0.4%CVE-2026-29172HIGHCraft Commerce has a SQL Injection in Commerce Purchasables Table SortingEPSS 0.4%CVE-2026-92593HIGHCraft CMS 5.10.0 before 5.10.13 Authenticated Remote Code ExecutionEPSS 0.4%CVE-2026-55793MEDIUMCraft CMS: Stored XSS via Structure entry title in table viewEPSS 0.4%CVE-2026-55794HIGHCraft CMS: Potential authenticated Remote Code Execution via referrer redirectEPSS 0.4%CVE-2023-31144MEDIUMCraft CMS vulnerable to cross site scripting in RSS feed widgetEPSS 0.4%CVE-2026-50280MEDIUMCraft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save checkEPSS 0.4%CVE-2026-55792MEDIUMCraft CMS: Sensitive File Disclosure / Server-Side File ReadEPSS 0.4%CVE-2026-86730HIGHCraft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCEEPSS 0.4%