craftcms/cms Security Advisories for 4.2.5.2 (21)
- 
                        [MEDIUM] Craft CMS Potential Remote Code Execution via Twig SSTIPKSA-cbq7-fhfn-fyt5 CVE-2025-57811 GHSA-crcq-738g-pqvc Affected version: >=5.0.0-RC1,<=5.8.6|>=4.0.0-RC1,<=4.16.5 Reported by: 
 GitHub
- 
                        [MEDIUM] Craft CMS stores arbitrary content provided by unauthenticated users in session filesPKSA-ht16-h36v-hxc7 CVE-2025-35939 GHSA-7vrx-9684-xrf2 Affected version: <4.15.3|>=5.0.0-alpha.1,<5.7.5 Reported by: 
 GitHub
- 
                        [HIGH] Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTIPKSA-8gxy-mg5h-z15w CVE-2025-46731 GHSA-7c58-g782-9j38 Affected version: >=5.0.0-RC1,<=5.6.14|>=4.0.0-RC1,<=4.14.12 Reported by: 
 GitHub
- 
                        [CRITICAL] Craft CMS Allows Remote Code ExecutionPKSA-5c44-5nbz-c7cq CVE-2025-32432 GHSA-f3gw-9ww9-jmc3 Affected version: >=5.0.0-RC1,<=5.6.16|>=4.0.0-RC1,<=4.14.14|>=3.0.0-RC1,<=3.9.14 Reported by: 
 GitHub
- 
                        [HIGH] Craft CMS has a potential RCE with a compromised security keyPKSA-nfqr-ns8g-wkkx CVE-2025-23209 GHSA-x684-96hh-833x Affected version: >=4.0.0-RC1,<4.13.8|>=5.0.0-RC1,<5.5.5 Reported by: 
 GitHub
- 
                        [CRITICAL] Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabledPKSA-xh7q-jwpn-v1cd CVE-2024-56145 GHSA-2p6p-9rc9-62j9 Affected version: >=3.0.0,<3.9.14|>=4.0.0-RC1,<4.13.2|>=5.0.0-RC1,<5.5.2 Reported by: 
 GitHub
- 
                        [HIGH] Craft CMS vulnerable to Potential Remote Code Execution via missing path normalization & Twig SSTIPKSA-4wwj-2m42-9pp5 CVE-2024-52293 GHSA-f3cw-hg6r-chfv Affected version: >=5.0.0-RC1,<=5.4.2|>=4.0.0-RC1,<=4.12.1 Reported by: 
 GitHub
- 
                        [HIGH] Craft CMS Arbitrary System File ReadPKSA-jkbm-w624-yb7q CVE-2024-52292 GHSA-cw6g-qmjq-6w2w Affected version: >=3.5.13,<=4.12.6.1|>=5.0.0-alpha.1,<=5.4.7.1 Reported by: 
 GitHub
- 
                        [HIGH] Local File System Validation Bypass Leading to File Overwrite, Sensitive File Access, and Potential Code ExecutionPKSA-mtjx-x487-29s9 CVE-2024-52291 GHSA-jrh5-vhr9-qh7q Affected version: >=4.0.0-RC1,<=4.12.4.1|>=5.0.0-RC1,<=5.4.5.1 Reported by: 
 GitHub
- 
                        [HIGH] Craft CMS Feed-MePKSA-yq9g-7wmy-ph9w CVE-2023-36260 GHSA-6p78-f7h9-6838 Affected version: <4.6.2 Reported by: 
 GitHub
- 
                        [MEDIUM] Craft CMS Privilege EscalationPKSA-gcgv-38nz-y8bs CVE-2024-21622 GHSA-j5g9-j7r4-6qvx Affected version: >=3.0.0,<=3.9.5|>=4.0.0-RC1,<=4.5.10 Reported by: 
 GitHub
- 
                        [CRITICAL] Craft CMS Remote Code Execution vulnerabilityPKSA-zdwv-2yjx-tdbf CVE-2023-41892 GHSA-4w8r-3xrw-v25g Affected version: >=4.0.0-RC1,<=4.4.14 Reported by: 
 GitHub
- 
                        [HIGH] Craft CMS vulnerable to Remote Code Execution via validatePath bypassPKSA-cdfq-1syy-3hcn CVE-2023-40035 GHSA-44wr-rmwq-3phw Affected version: >=3.0.0,<=3.8.14|>=4.0.0-RC1,<=4.4.14 Reported by: 
 GitHub
- 
                        [MEDIUM] Craft CMS vulnerable to HTML injectionPKSA-htxf-m811-km69 CVE-2023-33495 GHSA-m3v5-gjj9-rg24 Affected version: <=4.4.9 Reported by: 
 GitHub
- 
                        [MEDIUM] Stored cross site scripting in Craft CMSPKSA-j8mx-rm6f-69pz CVE-2023-2817 GHSA-7x94-jx75-3gh6 Affected version: >=4.0.0-RC1,<4.4.12 Reported by: 
 GitHub
- 
                        [MEDIUM] Craft CMS stored XSS in indexedVolumesPKSA-xrqk-w2n4-gbx4 CVE-2023-33197 GHSA-6qjx-787v-6pxr Affected version: >=4.0.0-RC1,<=4.4.5 Reported by: 
 GitHub
- 
                        [MEDIUM] Craft CMS stored XSS in review volumePKSA-d3nn-kdfd-kcm5 CVE-2023-33196 GHSA-cjmm-x9x9-m2w5 Affected version: >=4.0.0-RC1,<=4.4.6 Reported by: 
 GitHub
- 
                        [LOW] CraftCMS stored XSS in Quick Post widget error messagePKSA-yhf6-73qh-nrcp CVE-2023-33194 GHSA-3wxg-w96j-8hq9 Affected version: >=3.0.0,<=3.8.5|>=4.0.0-RC1,<4.4.6 Reported by: 
 GitHub
- 
                        [HIGH] Craft CMS vulnerable to Remote Code Execution via unrestricted file extensionPKSA-trjg-y1pb-yh98 CVE-2023-32679 GHSA-vqxf-r9ph-cc9c Affected version: >=4.0.0,<4.4.6 Reported by: 
 GitHub
- 
                        [MEDIUM] craftcms/cms vulnerable to cross site scripting in RSS feed widgetPKSA-wgr5-shk8-4nmh CVE-2023-31144 GHSA-j4mx-98hw-6rv6 Affected version: >=4.0.0,<=4.4.3|>=3.0.0,<=3.8.3 Reported by: 
 GitHub
- 
                        [MEDIUM] Craft CMS Stored Cross-site Scripting Injection VulnerabilityPKSA-y2n7-ny47-ym4h CVE-2023-23927 GHSA-qcrj-6ffc-v7hq Affected version: >=3.7.24,<3.7.64|>=4.0.0-RC1,<4.3.7 Reported by: 
 GitHub