Перейти к содержимому
Noroxi

Записи craftcms

114 опубликованных записей вендора craftcms.

Профиль для исследователя

Попали в KEV
4 · 3,5 %
С эксплойтом
5 · 4,4 %
Pre-auth RCE
8
С записью об исправлении
93 %
Медиана: публикация → KEV
100 дн.

Все записи

114 записей
  • CVE-2025-32432
    100Срочно

    Craft CMS Allows Remote Code Execution

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    craftcms · craft cms25 апр. 2025 г.

  • CVE-2024-56145
    96Срочно

    RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms

    КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 97 %

    craftcms · craft cms18 дек. 2024 г.

  • CVE-2025-23209
    69На этой неделе

    Potential RCE with a compromised security key in craft/cms

    ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 22 %

    craftcms · craft cms17 янв. 2025 г.

  • CVE-2023-41892
    67На этой неделе

    Craft CMS Remote Code Execution vulnerability

    КритическаяCVSS 9,8Готовый эксплойтEPSS 94 %

    craftcms · craft cms13 сент. 2023 г.

  • CVE-2020-9757
    61На этой неделе

    The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacont

    КритическаяCVSS 9,8Proof of conceptEPSS 73 %

    craftcms · craft cms4 мар. 2020 г.

  • CVE-2025-35939
    57В плане

    Craft CMS stores user-provided content in session files

    СредняяCVSS 6,9KEVГотовый эксплойтEPSS 1 %

    craftcms · craft cms7 мая 2025 г.

  • CVE-2024-37843
    55В плане

    Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.

    КритическаяCVSS 9,8Proof of conceptEPSS 53 %

    craftcms · craft cms25 июн. 2024 г.

  • CVE-2021-27903
    40В плане

    An issue was discovered in Craft CMS before 3.6.7.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    craftcms · craft cms30 июн. 2021 г.

  • CVE-2019-15929
    40В плане

    In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibil

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    craftcms · craft cms24 окт. 2019 г.

  • CVE-2026-28697
    37Наблюдать

    Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates

    КритическаяCVSS 9,4Эксплойта нетEPSS 1 %

    craftcms · craft cms4 мар. 2026 г.

  • CVE-2026-28783
    37Наблюдать

    Craft has a Twig Function Blocklist Bypass

    КритическаяCVSS 9,4Эксплойта нетEPSS 1 %

    craftcms · craft cms4 мар. 2026 г.

  • CVE-2022-29933
    36Наблюдать

    Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password an

    ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %

    craftcms · craft cms9 мая 2022 г.

  • CVE-2018-3814
    36Наблюдать

    Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    craftcms · craft cms1 янв. 2018 г.

  • CVE-2023-30130
    35Наблюдать

    An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    craftcms · craft cms12 мая 2023 г.

  • CVE-2021-41824
    35Наблюдать

    Craft CMS before 3.7.14 allows CSV injection.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    craftcms · craft cms29 сент. 2021 г.

  • CVE-2024-21622
    35Наблюдать

    Craft CMS Privilege Escalation

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    craftcms · craft cms3 янв. 2024 г.

  • CVE-2026-25498
    34Наблюдать

    Craft has a potential authenticated Remote Code Execution via malicious attached Behavior

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    craftcms · craft cms9 февр. 2026 г.

  • CVE-2026-33157
    34Наблюдать

    Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    craftcms · craft cms24 мар. 2026 г.

  • CVE-2025-68455
    34Наблюдать

    Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    craftcms · craft cms5 янв. 2026 г.

  • CVE-2026-32264
    34Наблюдать

    Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    craftcms · craft cms16 мар. 2026 г.

  • CVE-2026-32263
    34Наблюдать

    Craft CMS vulnerable to behavior injection RCE via EntryTypesController

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    craftcms · craft cms16 мар. 2026 г.

  • CVE-2026-28784
    34Наблюдать

    Craft is affected by potential authenticated Remote Code Execution via Twig SSTI

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    craftcms · craft cms4 мар. 2026 г.

  • CVE-2026-25495
    34Наблюдать

    Craft has a SQL Injection in Element Indexes via criteria[orderBy]

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    craftcms · craft cms9 февр. 2026 г.

  • CVE-2026-25497
    34Наблюдать

    Craft has a GraphQL Asset Mutation Privilege Escalation

    ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %

    craftcms · craft cms9 февр. 2026 г.

  • CVE-2026-29174
    34Наблюдать

    Craft Commerce has a SQL Injection in Commerce Inventory Table Sorting

    ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %

    craftcms · craft commerce10 мар. 2026 г.