craftcms kayıtları
craftcms üreticisine ait 114 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 4 · %3,5
- Silahlaştırılmış
- 5 · %4,4
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %93
- Yayından KEV’e ortanca
- 100 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')43
- CWE-94 Improper Control of Generation of Code ('Code Injection')9
- CWE-639 Authorization Bypass Through User-Controlled Key8
- CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-918 Server-Side Request Forgery (SSRF)5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
114 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2025-32432Silahlaştırılmış | Craft CMS Allows Remote Code Executioncraftcms · craft cms · CWE-94 | Kritik10,0 | KEV | %99,8 | 25 Nis 2025 |
96Hemen | CVE-2024-56145Silahlaştırılmış | RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cmscraftcms · craft cms · CWE-94 | Kritik9,3 | KEV | %97,4 | 18 Ara 2024 |
69Bu hafta | CVE-2025-23209Silahlaştırılmış | Potential RCE with a compromised security key in craft/cmscraftcms · craft cms · CWE-94 | Yüksek8,1 | KEV | %21,8 | 17 Oca 2025 |
67Bu hafta | CVE-2023-41892Silahlaştırılmış | Craft CMS Remote Code Execution vulnerabilitycraftcms · craft cms · CWE-94 | Kritik9,8 | — | %94,2 | 13 Eyl 2023 |
61Bu hafta | CVE-2020-9757Kavram kanıtı | The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontcraftcms · craft cms · CWE-74 | Kritik9,8 | — | %72,8 | 4 Mar 2020 |
57Planlayın | CVE-2025-35939Silahlaştırılmış | Craft CMS stores user-provided content in session filescraftcms · craft cms · CWE-472 | Orta6,9 | KEV | %1,3 | 7 May 2025 |
55Planlayın | CVE-2024-37843Kavram kanıtı | Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.craftcms · craft cms · CWE-89 | Kritik9,8 | — | %53,2 | 25 Haz 2024 |
40Planlayın | CVE-2021-27903İstismar yok | An issue was discovered in Craft CMS before 3.6.7.craftcms · craft cms · CWE-862 | Kritik9,8 | — | %2,8 | 30 Haz 2021 |
40Planlayın | CVE-2019-15929İstismar yok | In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibilcraftcms · craft cms · CWE-640 | Kritik9,8 | — | %1,8 | 24 Eki 2019 |
37İzleyin | CVE-2026-28697İstismar yok | Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templatescraftcms · craft cms · CWE-1336 | Kritik9,4 | — | %1,1 | 4 Mar 2026 |
37İzleyin | CVE-2026-28783İstismar yok | Craft has a Twig Function Blocklist Bypasscraftcms · craft cms · CWE-94 | Kritik9,4 | — | %0,5 | 4 Mar 2026 |
36İzleyin | CVE-2022-29933İstismar yok | Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password ancraftcms · craft cms · CWE-640 | Yüksek8,8 | — | %4,6 | 9 May 2022 |
36İzleyin | CVE-2018-3814İstismar yok | Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace itcraftcms · craft cms · CWE-434 | Yüksek8,8 | — | %1,9 | 1 Oca 2018 |
35İzleyin | CVE-2023-30130İstismar yok | An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.craftcms · craft cms · CWE-94 | Yüksek8,8 | — | %1,4 | 12 May 2023 |
35İzleyin | CVE-2021-41824İstismar yok | Craft CMS before 3.7.14 allows CSV injection.craftcms · craft cms · CWE-1236 | Yüksek8,8 | — | %1,4 | 29 Eyl 2021 |
35İzleyin | CVE-2024-21622İstismar yok | Craft CMS Privilege Escalationcraftcms · craft cms · CWE-269 | Yüksek8,8 | — | %0,6 | 3 Oca 2024 |
34İzleyin | CVE-2026-25498İstismar yok | Craft has a potential authenticated Remote Code Execution via malicious attached Behaviorcraftcms · craft cms · CWE-470 | Yüksek8,6 | — | %1,2 | 9 Şub 2026 |
34İzleyin | CVE-2026-33157İstismar yok | Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behaviorcraftcms · craft cms · CWE-470 | Yüksek8,6 | — | %1,1 | 24 Mar 2026 |
34İzleyin | CVE-2025-68455İstismar yok | Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behaviorcraftcms · craft cms · CWE-470 | Yüksek8,6 | — | %0,9 | 5 Oca 2026 |
34İzleyin | CVE-2026-32264İstismar yok | Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsControllercraftcms · craft cms · CWE-470 | Yüksek8,6 | — | %0,7 | 16 Mar 2026 |
34İzleyin | CVE-2026-32263İstismar yok | Craft CMS vulnerable to behavior injection RCE via EntryTypesControllercraftcms · craft cms · CWE-470 | Yüksek8,6 | — | %0,7 | 16 Mar 2026 |
34İzleyin | CVE-2026-28784İstismar yok | Craft is affected by potential authenticated Remote Code Execution via Twig SSTIcraftcms · craft cms · CWE-1336 | Yüksek8,6 | — | %0,6 | 4 Mar 2026 |
34İzleyin | CVE-2026-25495İstismar yok | Craft has a SQL Injection in Element Indexes via criteria[orderBy]craftcms · craft cms · CWE-89 | Yüksek8,7 | — | %0,6 | 9 Şub 2026 |
34İzleyin | CVE-2026-25497İstismar yok | Craft has a GraphQL Asset Mutation Privilege Escalationcraftcms · craft cms · CWE-639 | Yüksek8,6 | — | %0,5 | 9 Şub 2026 |
34İzleyin | CVE-2026-29174İstismar yok | Craft Commerce has a SQL Injection in Commerce Inventory Table Sortingcraftcms · craft commerce · CWE-89 | Yüksek8,7 | — | %0,5 | 10 Mar 2026 |
- CVE-2025-32432100Hemen
Craft CMS Allows Remote Code Execution
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100craftcms · craft cms25 Nis 2025
- CVE-2024-5614596Hemen
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
KritikCVSS 9,3KEVSilahlaştırılmışEPSS %97craftcms · craft cms18 Ara 2024
- CVE-2025-2320969Bu hafta
Potential RCE with a compromised security key in craft/cms
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %22craftcms · craft cms17 Oca 2025
- CVE-2023-4189267Bu hafta
Craft CMS Remote Code Execution vulnerability
KritikCVSS 9,8SilahlaştırılmışEPSS %94craftcms · craft cms13 Eyl 2023
- CVE-2020-975761Bu hafta
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacont
KritikCVSS 9,8Kavram kanıtıEPSS %73craftcms · craft cms4 Mar 2020
- CVE-2025-3593957Planlayın
Craft CMS stores user-provided content in session files
OrtaCVSS 6,9KEVSilahlaştırılmışEPSS %1craftcms · craft cms7 May 2025
- CVE-2024-3784355Planlayın
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
KritikCVSS 9,8Kavram kanıtıEPSS %53craftcms · craft cms25 Haz 2024
- CVE-2021-2790340Planlayın
An issue was discovered in Craft CMS before 3.6.7.
KritikCVSS 9,8İstismar yokEPSS %3craftcms · craft cms30 Haz 2021
- CVE-2019-1592940Planlayın
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibil
KritikCVSS 9,8İstismar yokEPSS %2craftcms · craft cms24 Eki 2019
- CVE-2026-2869737İzleyin
Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates
KritikCVSS 9,4İstismar yokEPSS %1craftcms · craft cms4 Mar 2026
- CVE-2026-2878337İzleyin
Craft has a Twig Function Blocklist Bypass
KritikCVSS 9,4İstismar yokEPSS %1craftcms · craft cms4 Mar 2026
- CVE-2022-2993336İzleyin
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password an
YüksekCVSS 8,8İstismar yokEPSS %5craftcms · craft cms9 May 2022
- CVE-2018-381436İzleyin
Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it
YüksekCVSS 8,8İstismar yokEPSS %2craftcms · craft cms1 Oca 2018
- CVE-2023-3013035İzleyin
An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.
YüksekCVSS 8,8İstismar yokEPSS %1craftcms · craft cms12 May 2023
- CVE-2021-4182435İzleyin
Craft CMS before 3.7.14 allows CSV injection.
YüksekCVSS 8,8İstismar yokEPSS %1craftcms · craft cms29 Eyl 2021
- CVE-2024-2162235İzleyin
Craft CMS Privilege Escalation
YüksekCVSS 8,8İstismar yokEPSS %1craftcms · craft cms3 Oca 2024
- CVE-2026-2549834İzleyin
Craft has a potential authenticated Remote Code Execution via malicious attached Behavior
YüksekCVSS 8,6İstismar yokEPSS %1craftcms · craft cms9 Şub 2026
- CVE-2026-3315734İzleyin
Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior
YüksekCVSS 8,6İstismar yokEPSS %1craftcms · craft cms24 Mar 2026
- CVE-2025-6845534İzleyin
Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
YüksekCVSS 8,6İstismar yokEPSS %1craftcms · craft cms5 Oca 2026
- CVE-2026-3226434İzleyin
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
YüksekCVSS 8,6İstismar yokEPSS %1craftcms · craft cms16 Mar 2026
- CVE-2026-3226334İzleyin
Craft CMS vulnerable to behavior injection RCE via EntryTypesController
YüksekCVSS 8,6İstismar yokEPSS %1craftcms · craft cms16 Mar 2026
- CVE-2026-2878434İzleyin
Craft is affected by potential authenticated Remote Code Execution via Twig SSTI
YüksekCVSS 8,6İstismar yokEPSS %1craftcms · craft cms4 Mar 2026
- CVE-2026-2549534İzleyin
Craft has a SQL Injection in Element Indexes via criteria[orderBy]
YüksekCVSS 8,7İstismar yokEPSS %1craftcms · craft cms9 Şub 2026
- CVE-2026-2549734İzleyin
Craft has a GraphQL Asset Mutation Privilege Escalation
YüksekCVSS 8,6İstismar yokEPSS %1craftcms · craft cms9 Şub 2026
- CVE-2026-2917434İzleyin
Craft Commerce has a SQL Injection in Commerce Inventory Table Sorting
YüksekCVSS 8,7İstismar yokEPSS %1craftcms · craft commerce10 Mar 2026