craftcms
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting craftcms.
- CVE-2026-72785Craft CMS before 5.10.6 Authorization Bypass via structures/move-element4.3
- CVE-2026-72784Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutation5.4
- CVE-2026-72782Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leak6.5
- CVE-2026-72783Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContained6.2
- CVE-2026-72781Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escape8.8
- CVE-2026-72780Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey6.5
- CVE-2026-72779Craft CMS 5.0.0-RC1 before 5.10.6 Arbitrary File Read via SplFileObject4.5
- CVE-2026-72778Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config8.8
- CVE-2026-56394Craft CMS - Authenticated Path Traversal in assets/icon Extension Parameter6.5
- CVE-2026-56385Craft CMS - Authorization Bypass in assets/preview-file Endpoint4.3
- CVE-2026-56393Craft CMS - Multiple Stored Cross-Site Scripting in Settings Names and Field Options4.8
- CVE-2026-56384Craft CMS - Missing Authorization in assets/preview-thumb Endpoint4.3
- CVE-2026-56383Craft CMS - Stored XSS in Table Field via Row Heading Column Type4.8
- CVE-2026-56381Craft CMS - Stored XSS via User Group Name in User Permissions Page4.8
- CVE-2026-56382Craft CMS - Remote Code Execution via Missing Config Sanitization in FieldsController7.2