craftcms/cms Security Advisories (48)
-
[HIGH] Craft CMS has a potential RCE with a compromised security key
PKSA-nfqr-ns8g-wkkx CVE-2025-23209 GHSA-x684-96hh-833x
Affected version: >=4.0.0-RC1,<4.13.8|>=5.0.0-RC1,<5.5.5
Reported by:
GitHub -
[CRITICAL] Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled
PKSA-xh7q-jwpn-v1cd CVE-2024-56145 GHSA-2p6p-9rc9-62j9
Affected version: >=3.0.0,<3.9.14|>=4.0.0-RC1,<4.13.2|>=5.0.0-RC1,<5.5.2
Reported by:
GitHub -
[HIGH] Craft CMS vulnerable to Potential Remote Code Execution via missing path normalization & Twig SSTI
PKSA-4wwj-2m42-9pp5 CVE-2024-52293 GHSA-f3cw-hg6r-chfv
Affected version: >=5.0.0-RC1,<=5.4.2|>=4.0.0-RC1,<=4.12.1
Reported by:
GitHub -
[HIGH] Craft CMS Arbitrary System File Read
PKSA-jkbm-w624-yb7q CVE-2024-52292 GHSA-cw6g-qmjq-6w2w
Affected version: >=3.5.13,<=4.12.6.1|>=5.0.0-alpha.1,<=5.4.7.1
Reported by:
GitHub -
[HIGH] Local File System Validation Bypass Leading to File Overwrite, Sensitive File Access, and Potential Code Execution
PKSA-mtjx-x487-29s9 CVE-2024-52291 GHSA-jrh5-vhr9-qh7q
Affected version: >=4.0.0-RC1,<=4.12.4.1|>=5.0.0-RC1,<=5.4.5.1
Reported by:
GitHub -
[MEDIUM] Craft CMS vulnerable to stored XSS in breadcrumb list and title fields
PKSA-8qn2-9hhy-cmx1 CVE-2024-45406 GHSA-28h4-788g-rh42
Affected version: >=5.0.0,<5.1.2
Reported by:
GitHub -
[MEDIUM] Craft CMS Allows TOTP Token To Stay Valid After Use
PKSA-56qm-r9zg-vprk CVE-2024-41800 GHSA-wmx7-pw49-88jx
Affected version: >=5.0.0-beta.1,<=5.2.2
Reported by:
GitHub -
[CRITICAL] Craft CMS SQL injection vulnerability via the GraphQL API endpoint
PKSA-5d9d-qr6t-qn95 CVE-2024-37843 GHSA-hq4f-mv3q-8wcv
Affected version: <=3.7.31
Reported by:
GitHub -
[HIGH] Craft CMS Feed-Me
PKSA-yq9g-7wmy-ph9w CVE-2023-36260 GHSA-6p78-f7h9-6838
Affected version: <4.6.2
Reported by:
GitHub -
[MEDIUM] Craft CMS Privilege Escalation
PKSA-gcgv-38nz-y8bs CVE-2024-21622 GHSA-j5g9-j7r4-6qvx
Affected version: >=3.0.0,<=3.9.5|>=4.0.0-RC1,<=4.5.10
Reported by:
GitHub -
[CRITICAL] Craft CMS Remote Code Execution vulnerability
PKSA-zdwv-2yjx-tdbf CVE-2023-41892 GHSA-4w8r-3xrw-v25g
Affected version: >=4.0.0-RC1,<=4.4.14
Reported by:
GitHub -
[HIGH] Craft CMS vulnerable to Remote Code Execution via validatePath bypass
PKSA-cdfq-1syy-3hcn CVE-2023-40035 GHSA-44wr-rmwq-3phw
Affected version: >=3.0.0,<=3.8.14|>=4.0.0-RC1,<=4.4.14
Reported by:
GitHub -
[MEDIUM] Craft CMS vulnerable to HTML injection
PKSA-htxf-m811-km69 CVE-2023-33495 GHSA-m3v5-gjj9-rg24
Affected version: <=4.4.9
Reported by:
GitHub -
[MEDIUM] Stored cross site scripting in Craft CMS
PKSA-j8mx-rm6f-69pz CVE-2023-2817 GHSA-7x94-jx75-3gh6
Affected version: >=4.0.0-RC1,<4.4.12
Reported by:
GitHub -
[MEDIUM] Craft CMS stored XSS in indexedVolumes
PKSA-xrqk-w2n4-gbx4 CVE-2023-33197 GHSA-6qjx-787v-6pxr
Affected version: >=4.0.0-RC1,<=4.4.5
Reported by:
GitHub -
[MEDIUM] Craft CMS stored XSS in review volume
PKSA-d3nn-kdfd-kcm5 CVE-2023-33196 GHSA-cjmm-x9x9-m2w5
Affected version: >=4.0.0-RC1,<=4.4.6
Reported by:
GitHub -
[MEDIUM] Craft CMS XSS in RSS widget feed
PKSA-nyt9-b7wg-tdq3 CVE-2023-33195 GHSA-qpgm-gjgf-8c2x
Affected version: >=4.3.0,<=4.4.5
Reported by:
GitHub -
[LOW] CraftCMS stored XSS in Quick Post widget error message
PKSA-yhf6-73qh-nrcp CVE-2023-33194 GHSA-3wxg-w96j-8hq9
Affected version: >=3.0.0,<=3.8.5|>=4.0.0-RC1,<4.4.6
Reported by:
GitHub -
[HIGH] Craft CMS vulnerable to Remote Code Execution via unrestricted file extension
PKSA-trjg-y1pb-yh98 CVE-2023-32679 GHSA-vqxf-r9ph-cc9c
Affected version: >=4.0.0,<4.4.6
Reported by:
GitHub -
[HIGH] CraftCMS allows remote attacker to execute arbitrary code via crafted script to Section parameter
PKSA-2kbt-tv7g-v7px CVE-2023-30130 GHSA-fjx5-xm7q-whvj
Affected version: <=3.8.1
Reported by:
GitHub -
[MEDIUM] craftcms/cms vulnerable to cross site scripting in RSS feed widget
PKSA-wgr5-shk8-4nmh CVE-2023-31144 GHSA-j4mx-98hw-6rv6
Affected version: >=4.0.0,<=4.4.3|>=3.0.0,<=3.8.3
Reported by:
GitHub -
[MEDIUM] Cross Site Scripting in CraftCMS
PKSA-t4fh-cwff-qj8q CVE-2023-30177 GHSA-wv7j-rc2q-9j67
Affected version: <3.7.68
Reported by:
GitHub -
[MEDIUM] Craft CMS Stored Cross-site Scripting Injection Vulnerability
PKSA-y2n7-ny47-ym4h CVE-2023-23927 GHSA-qcrj-6ffc-v7hq
Affected version: >=3.7.24,<3.7.64|>=4.0.0-RC1,<4.3.7
Reported by:
GitHub -
[HIGH] Craft CMS discloses password hashes
PKSA-rgy6-34nm-mk1h CVE-2022-37783 GHSA-h972-v458-m892
Affected version: >=3.0.0,<=3.7.32
Reported by:
GitHub -
[MEDIUM] Craft CMS Cross-site Scripting vulnerability
PKSA-nm2h-kht2-h3cj CVE-2022-37246 GHSA-f546-v666-559x
Affected version: >=3.7.39,<3.7.51|>=4.0.0-RC1,<4.2.1
Reported by:
GitHub -
[MEDIUM] Craft CMS Stored Cross-site Scripting in User Addresses Title
PKSA-fjpm-r2z5-3msf CVE-2022-37250 GHSA-8r89-x93x-mjq2
Affected version: >=4.0.0-RC1,<4.2.1
Reported by:
GitHub -
[MEDIUM] Craft CMS Cross site Scripting vulnerability
PKSA-1cn6-mp7y-tdn1 CVE-2022-37248 GHSA-wxvf-839f-jqmh
Affected version: >=4.0.0-RC1,<4.2.1
Reported by:
GitHub -
[MEDIUM] Craft CMS vulnerable to Cross-site Scripting via entry revisions and drafts
PKSA-hq26-n3zb-ct5n CVE-2022-37251 GHSA-mw37-wx8p-gp45
Affected version: >=4.0.0-RC1,<4.2.1|>=3.7.0-beta.1,<3.7.55.2
Reported by:
GitHub -
[MEDIUM] Craft CMS vulnerable to stored Cross-site Scripting via /admin/settings/fields page
PKSA-qn7t-x4ck-qyd5 CVE-2022-37247 GHSA-3cvm-7wrh-qrf9
Affected version: >=4.0.0-RC1,<4.2.1
Reported by:
GitHub -
[MEDIUM] Craft CMS Cross-site Scripting Vulnerability
PKSA-ngqg-qdtb-rm3d CVE-2020-19626 GHSA-33jj-92px-m4g7
Affected version: <3.1.33
Reported by:
GitHub -
[CRITICAL] Craft CMS possibility of brute force attempts
PKSA-1y5n-q5z7-8cgs CVE-2019-15929 GHSA-wvr4-w6cw-4px8
Affected version: <3.1.7
Reported by:
GitHub -
[MEDIUM] Craft CMS XSS Vulnerability
PKSA-5swg-jxtx-ftv4 CVE-2019-17496 GHSA-f3xr-q258-h7m9
Affected version: <3.3.8
Reported by:
GitHub -
[MEDIUM] Craft CMS XSS Vulnerability
PKSA-fv5t-gxkj-6y82 CVE-2019-12823 GHSA-w5q4-q7wp-qww6
Affected version: <3.1.31
Reported by:
GitHub -
[MEDIUM] Craft CMS XSS Vulnerability
PKSA-kq4p-4cmz-my81 CVE-2017-8052 GHSA-xv5f-2997-qhrq
Affected version: <2.6.2974
Reported by:
GitHub -
[MEDIUM] Craft CMS subject to URL forgery
PKSA-2z2h-k3wy-w25s CVE-2017-8385 GHSA-j27g-r58q-624w
Affected version: <2.6.2976
Reported by:
GitHub -
[MEDIUM] Craft CMS XSS Vulnerability
PKSA-ghfb-4pk5-qhrj CVE-2017-8384 GHSA-9mcw-mwxv-grwj
Affected version: <2.6.2976
Reported by:
GitHub -
[MEDIUM] Craft CMS XSS Vulnerability
PKSA-gpt3-vsnf-hfrt CVE-2017-9516 GHSA-6pvw-hh48-jx7p
Affected version: <2.6.2982
Reported by:
GitHub -
[MEDIUM] Craft CMS Cross-site Scripting (XSS) Vulnerability
PKSA-4gm9-3p9z-44t6 CVE-2018-20418 GHSA-72pf-cvwq-vgqg
Affected version: <=3.0.25
Reported by:
GitHub -
[HIGH] Craft CMS Vulnerable to Server-Side Template Injection
PKSA-9b83-4qd6-4szn CVE-2018-20465 GHSA-j7fx-v37j-v3w7
Affected version: <=3.0.34
Reported by:
GitHub -
[MEDIUM] Craft CMS Unauthorized View
PKSA-3cvb-x36b-p3nr CVE-2017-8383 GHSA-7qq6-fgpw-xw45
Affected version: <2.6.2976
Reported by:
GitHub -
[HIGH] Craft CMS PHP Code Injection Vulnerability
PKSA-f9g7-q3qs-w8nw CVE-2018-3814 GHSA-r342-vjc4-wrmj
Affected version: <=2.6.3000
Reported by:
GitHub -
[HIGH] Improper account password reset in Craft CMS
PKSA-61st-bdmf-2n6s CVE-2022-29933 GHSA-5cjr-78cq-3wrg
Affected version: <3.7.36
Reported by:
GitHub -
Reported by:
GitHub -
[MEDIUM] Cross-site Scripting in craftcms/cms
PKSA-1ktx-1md2-qf47 CVE-2022-28378 GHSA-7xj5-fwqr-5378
Affected version: <3.7.29
Reported by:
GitHub -
[MEDIUM] Craft CMS Cross-site Scripting Vulnerability
PKSA-n1f2-zc53-b6z3 CVE-2021-32470 GHSA-h2rj-8wgg-mm43
Affected version: <3.6.13
Reported by:
GitHub -
[HIGH] CSV Injection Vulnerability
PKSA-6q3k-247g-652k CVE-2021-41824 GHSA-h7vq-5qgw-jwwq
Affected version: >=3.4.0,<3.7.14
Reported by:
GitHub -
[CRITICAL] Craft CMS Remote Code Injection
PKSA-fqry-snd1-rj28 CVE-2021-27903 GHSA-x2j7-6hxm-87p3
Affected version: <3.6.7
Reported by:
GitHub -
[MEDIUM] Craft CMS Cross-site Scripting Vulnerability
PKSA-p8kz-63g9-6c6r CVE-2021-27902 GHSA-3jxh-789f-p7m6
Affected version: <3.6.0
Reported by:
GitHub