craftcms records
114 published records for vendor craftcms.
Researcher profile
- Entered KEV
- 4 · 3.5%
- Weaponized
- 5 · 4.4%
- Pre-auth RCE
- 8
- With a fix record
- 93%
- Median publish → KEV
- 100 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')43
- CWE-94 Improper Control of Generation of Code ('Code Injection')9
- CWE-639 Authorization Bypass Through User-Controlled Key8
- CWE-1336 Improper Neutralization of Special Elements Used in a Template Engine6
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')5
- CWE-918 Server-Side Request Forgery (SSRF)5
The weakness classes this vendor ships most often: where to look.
CWEAll records
114 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2025-32432Weaponized | Craft CMS Allows Remote Code Executioncraftcms · craft cms · CWE-94 | Critical10.0 | KEV | 99.8% | Apr 25, 2025 |
96Now | CVE-2024-56145Weaponized | RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cmscraftcms · craft cms · CWE-94 | Critical9.3 | KEV | 97.4% | Dec 18, 2024 |
69This week | CVE-2025-23209Weaponized | Potential RCE with a compromised security key in craft/cmscraftcms · craft cms · CWE-94 | High8.1 | KEV | 21.8% | Jan 17, 2025 |
67This week | CVE-2023-41892Weaponized | Craft CMS Remote Code Execution vulnerabilitycraftcms · craft cms · CWE-94 | Critical9.8 | — | 94.2% | Sep 13, 2023 |
61This week | CVE-2020-9757Proof of concept | The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontcraftcms · craft cms · CWE-74 | Critical9.8 | — | 72.8% | Mar 4, 2020 |
57Plan | CVE-2025-35939Weaponized | Craft CMS stores user-provided content in session filescraftcms · craft cms · CWE-472 | Medium6.9 | KEV | 1.3% | May 7, 2025 |
55Plan | CVE-2024-37843Proof of concept | Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.craftcms · craft cms · CWE-89 | Critical9.8 | — | 53.2% | Jun 25, 2024 |
40Plan | CVE-2021-27903No exploit | An issue was discovered in Craft CMS before 3.6.7.craftcms · craft cms · CWE-862 | Critical9.8 | — | 2.8% | Jun 30, 2021 |
40Plan | CVE-2019-15929No exploit | In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibilcraftcms · craft cms · CWE-640 | Critical9.8 | — | 1.8% | Oct 24, 2019 |
37Monitor | CVE-2026-28697No exploit | Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templatescraftcms · craft cms · CWE-1336 | Critical9.4 | — | 1.1% | Mar 4, 2026 |
37Monitor | CVE-2026-28783No exploit | Craft has a Twig Function Blocklist Bypasscraftcms · craft cms · CWE-94 | Critical9.4 | — | 0.5% | Mar 4, 2026 |
36Monitor | CVE-2022-29933No exploit | Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password ancraftcms · craft cms · CWE-640 | High8.8 | — | 4.6% | May 9, 2022 |
36Monitor | CVE-2018-3814No exploit | Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace itcraftcms · craft cms · CWE-434 | High8.8 | — | 1.9% | Jan 1, 2018 |
35Monitor | CVE-2023-30130No exploit | An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.craftcms · craft cms · CWE-94 | High8.8 | — | 1.4% | May 12, 2023 |
35Monitor | CVE-2021-41824No exploit | Craft CMS before 3.7.14 allows CSV injection.craftcms · craft cms · CWE-1236 | High8.8 | — | 1.4% | Sep 29, 2021 |
35Monitor | CVE-2024-21622No exploit | Craft CMS Privilege Escalationcraftcms · craft cms · CWE-269 | High8.8 | — | 0.6% | Jan 3, 2024 |
34Monitor | CVE-2026-25498No exploit | Craft has a potential authenticated Remote Code Execution via malicious attached Behaviorcraftcms · craft cms · CWE-470 | High8.6 | — | 1.2% | Feb 9, 2026 |
34Monitor | CVE-2026-33157No exploit | Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behaviorcraftcms · craft cms · CWE-470 | High8.6 | — | 1.1% | Mar 24, 2026 |
34Monitor | CVE-2025-68455No exploit | Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behaviorcraftcms · craft cms · CWE-470 | High8.6 | — | 0.9% | Jan 5, 2026 |
34Monitor | CVE-2026-32264No exploit | Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsControllercraftcms · craft cms · CWE-470 | High8.6 | — | 0.7% | Mar 16, 2026 |
34Monitor | CVE-2026-32263No exploit | Craft CMS vulnerable to behavior injection RCE via EntryTypesControllercraftcms · craft cms · CWE-470 | High8.6 | — | 0.7% | Mar 16, 2026 |
34Monitor | CVE-2026-28784No exploit | Craft is affected by potential authenticated Remote Code Execution via Twig SSTIcraftcms · craft cms · CWE-1336 | High8.6 | — | 0.6% | Mar 4, 2026 |
34Monitor | CVE-2026-25495No exploit | Craft has a SQL Injection in Element Indexes via criteria[orderBy]craftcms · craft cms · CWE-89 | High8.7 | — | 0.6% | Feb 9, 2026 |
34Monitor | CVE-2026-25497No exploit | Craft has a GraphQL Asset Mutation Privilege Escalationcraftcms · craft cms · CWE-639 | High8.6 | — | 0.5% | Feb 9, 2026 |
34Monitor | CVE-2026-29174No exploit | Craft Commerce has a SQL Injection in Commerce Inventory Table Sortingcraftcms · craft commerce · CWE-89 | High8.7 | — | 0.5% | Mar 10, 2026 |
- CVE-2025-32432100Now
Craft CMS Allows Remote Code Execution
CriticalCVSS 10.0KEVWeaponizedEPSS 100%craftcms · craft cmsApr 25, 2025
- CVE-2024-5614596Now
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
CriticalCVSS 9.3KEVWeaponizedEPSS 97%craftcms · craft cmsDec 18, 2024
- CVE-2025-2320969This week
Potential RCE with a compromised security key in craft/cms
HighCVSS 8.1KEVWeaponizedEPSS 22%craftcms · craft cmsJan 17, 2025
- CVE-2023-4189267This week
Craft CMS Remote Code Execution vulnerability
CriticalCVSS 9.8WeaponizedEPSS 94%craftcms · craft cmsSep 13, 2023
- CVE-2020-975761This week
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacont
CriticalCVSS 9.8Proof of conceptEPSS 73%craftcms · craft cmsMar 4, 2020
- CVE-2025-3593957Plan
Craft CMS stores user-provided content in session files
MediumCVSS 6.9KEVWeaponizedEPSS 1%craftcms · craft cmsMay 7, 2025
- CVE-2024-3784355Plan
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
CriticalCVSS 9.8Proof of conceptEPSS 53%craftcms · craft cmsJun 25, 2024
- CVE-2021-2790340Plan
An issue was discovered in Craft CMS before 3.6.7.
CriticalCVSS 9.8No exploitEPSS 3%craftcms · craft cmsJun 30, 2021
- CVE-2019-1592940Plan
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibil
CriticalCVSS 9.8No exploitEPSS 2%craftcms · craft cmsOct 24, 2019
- CVE-2026-2869737Monitor
Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates
CriticalCVSS 9.4No exploitEPSS 1%craftcms · craft cmsMar 4, 2026
- CVE-2026-2878337Monitor
Craft has a Twig Function Blocklist Bypass
CriticalCVSS 9.4No exploitEPSS 1%craftcms · craft cmsMar 4, 2026
- CVE-2022-2993336Monitor
Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password an
HighCVSS 8.8No exploitEPSS 5%craftcms · craft cmsMay 9, 2022
- CVE-2018-381436Monitor
Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it
HighCVSS 8.8No exploitEPSS 2%craftcms · craft cmsJan 1, 2018
- CVE-2023-3013035Monitor
An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.
HighCVSS 8.8No exploitEPSS 1%craftcms · craft cmsMay 12, 2023
- CVE-2021-4182435Monitor
Craft CMS before 3.7.14 allows CSV injection.
HighCVSS 8.8No exploitEPSS 1%craftcms · craft cmsSep 29, 2021
- CVE-2024-2162235Monitor
Craft CMS Privilege Escalation
HighCVSS 8.8No exploitEPSS 1%craftcms · craft cmsJan 3, 2024
- CVE-2026-2549834Monitor
Craft has a potential authenticated Remote Code Execution via malicious attached Behavior
HighCVSS 8.6No exploitEPSS 1%craftcms · craft cmsFeb 9, 2026
- CVE-2026-3315734Monitor
Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior
HighCVSS 8.6No exploitEPSS 1%craftcms · craft cmsMar 24, 2026
- CVE-2025-6845534Monitor
Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
HighCVSS 8.6No exploitEPSS 1%craftcms · craft cmsJan 5, 2026
- CVE-2026-3226434Monitor
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
HighCVSS 8.6No exploitEPSS 1%craftcms · craft cmsMar 16, 2026
- CVE-2026-3226334Monitor
Craft CMS vulnerable to behavior injection RCE via EntryTypesController
HighCVSS 8.6No exploitEPSS 1%craftcms · craft cmsMar 16, 2026
- CVE-2026-2878434Monitor
Craft is affected by potential authenticated Remote Code Execution via Twig SSTI
HighCVSS 8.6No exploitEPSS 1%craftcms · craft cmsMar 4, 2026
- CVE-2026-2549534Monitor
Craft has a SQL Injection in Element Indexes via criteria[orderBy]
HighCVSS 8.7No exploitEPSS 1%craftcms · craft cmsFeb 9, 2026
- CVE-2026-2549734Monitor
Craft has a GraphQL Asset Mutation Privilege Escalation
HighCVSS 8.6No exploitEPSS 1%craftcms · craft cmsFeb 9, 2026
- CVE-2026-2917434Monitor
Craft Commerce has a SQL Injection in Commerce Inventory Table Sorting
HighCVSS 8.7No exploitEPSS 1%craftcms · craft commerceMar 10, 2026