craftcms/cms Security Advisories for 5.8.10 (5)
-
[HIGH] Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
PKSA-hcvs-d728-5zyw CVE-2025-68455 GHSA-255j-qw47-wjh5
Affected version: >=4.0.0-RC1,<=4.16.16|>=5.0.0-RC1,<=5.8.20
Reported by:
GitHub -
[HIGH] Unauthenticated Craft CMS users can trigger a database backup
PKSA-17hr-tk5g-ht8k CVE-2025-68456 GHSA-v64r-7wg9-23pr
Affected version: >=3.0.0,<=4.16.16|>=5.0.0-RC1,<=5.8.20
Reported by:
GitHub -
[MEDIUM] Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI
PKSA-9rbz-gy92-qjtd CVE-2025-68454 GHSA-742x-x762-7383
Affected version: >=4.0.0-RC1,<=4.16.16|>=5.0.0-RC1,<=5.8.20
Reported by:
GitHub -
[MEDIUM] Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation
PKSA-4gr3-459g-ssmq CVE-2025-68437 GHSA-x27p-wfqw-hfcc
Affected version: >=3.5.0,<=4.16.16|>=5.0.0-RC1,<=5.8.20
Reported by:
GitHub -
[MEDIUM] Craft CMS vulnerable to potential information disclosure via unchecked asset relocation
PKSA-yj3g-znh5-93sd CVE-2025-68436 GHSA-53vf-c43h-j2x9
Affected version: >=4.0.0-RC1,<=4.16.16|>=5.0.0-RC1,<=5.8.20
Reported by:
GitHub