Skip to content
Noroxi

craftcms records

114 published records for vendor craftcms.

All records

114 records
  • Craft CMS Allows Remote Code Execution

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    craftcms · craft cmsApr 25, 2025

  • RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms

    CriticalCVSS 9.3KEVWeaponizedEPSS 97%

    craftcms · craft cmsDec 18, 2024

  • CVE-2025-23209
    69This week

    Potential RCE with a compromised security key in craft/cms

    HighCVSS 8.1KEVWeaponizedEPSS 22%

    craftcms · craft cmsJan 17, 2025

  • CVE-2023-41892
    67This week

    Craft CMS Remote Code Execution vulnerability

    CriticalCVSS 9.8WeaponizedEPSS 94%

    craftcms · craft cmsSep 13, 2023

  • CVE-2020-9757
    61This week

    The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacont

    CriticalCVSS 9.8Proof of conceptEPSS 73%

    craftcms · craft cmsMar 4, 2020

  • Craft CMS stores user-provided content in session files

    MediumCVSS 6.9KEVWeaponizedEPSS 1%

    craftcms · craft cmsMay 7, 2025

  • Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.

    CriticalCVSS 9.8Proof of conceptEPSS 53%

    craftcms · craft cmsJun 25, 2024

  • An issue was discovered in Craft CMS before 3.6.7.

    CriticalCVSS 9.8No exploitEPSS 3%

    craftcms · craft cmsJun 30, 2021

  • In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibil

    CriticalCVSS 9.8No exploitEPSS 2%

    craftcms · craft cmsOct 24, 2019

  • Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates

    CriticalCVSS 9.4No exploitEPSS 1%

    craftcms · craft cmsMar 4, 2026

  • Craft has a Twig Function Blocklist Bypass

    CriticalCVSS 9.4No exploitEPSS 1%

    craftcms · craft cmsMar 4, 2026

  • Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password an

    HighCVSS 8.8No exploitEPSS 5%

    craftcms · craft cmsMay 9, 2022

  • CVE-2018-3814
    36Monitor

    Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it

    HighCVSS 8.8No exploitEPSS 2%

    craftcms · craft cmsJan 1, 2018

  • An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.

    HighCVSS 8.8No exploitEPSS 1%

    craftcms · craft cmsMay 12, 2023

  • Craft CMS before 3.7.14 allows CSV injection.

    HighCVSS 8.8No exploitEPSS 1%

    craftcms · craft cmsSep 29, 2021

  • Craft CMS Privilege Escalation

    HighCVSS 8.8No exploitEPSS 1%

    craftcms · craft cmsJan 3, 2024

  • Craft has a potential authenticated Remote Code Execution via malicious attached Behavior

    HighCVSS 8.6No exploitEPSS 1%

    craftcms · craft cmsFeb 9, 2026

  • Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior

    HighCVSS 8.6No exploitEPSS 1%

    craftcms · craft cmsMar 24, 2026

  • Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior

    HighCVSS 8.6No exploitEPSS 1%

    craftcms · craft cmsJan 5, 2026

  • Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController

    HighCVSS 8.6No exploitEPSS 1%

    craftcms · craft cmsMar 16, 2026

  • Craft CMS vulnerable to behavior injection RCE via EntryTypesController

    HighCVSS 8.6No exploitEPSS 1%

    craftcms · craft cmsMar 16, 2026

  • Craft is affected by potential authenticated Remote Code Execution via Twig SSTI

    HighCVSS 8.6No exploitEPSS 1%

    craftcms · craft cmsMar 4, 2026

  • Craft has a SQL Injection in Element Indexes via criteria[orderBy]

    HighCVSS 8.7No exploitEPSS 1%

    craftcms · craft cmsFeb 9, 2026

  • Craft has a GraphQL Asset Mutation Privilege Escalation

    HighCVSS 8.6No exploitEPSS 1%

    craftcms · craft cmsFeb 9, 2026

  • Craft Commerce has a SQL Injection in Commerce Inventory Table Sorting

    HighCVSS 8.7No exploitEPSS 1%

    craftcms · craft commerceMar 10, 2026