craftcms
Latest CVEs
The 15 most recently published vulnerabilities affecting craftcms.
- CVE-2026-92594Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL7.5
- CVE-2026-92593Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution8.8
- CVE-2026-92592Craft CMS before 4.18.6 Remote Code Execution via signed cookie8.8
- CVE-2026-92591Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer5.9
- CVE-2026-92590Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields5.4
- CVE-2026-92589Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder4.3
- CVE-2026-55795Craft Commerce: Coupon Code Brute-Force via Rate Limit Bypass
- CVE-2026-79987Low-privilege RCE through element-search eager loading8.8
- CVE-2026-86732Craft CMS before 5.10.12 Remote Code Execution via element-index8.8
- CVE-2026-86731Craft CMS 5.0.0-RC1 before 5.10.12 Permission Escalation via UsersController6.5
- CVE-2026-86730Craft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCE8.8
- CVE-2026-79991Authenticated SQL Injection via nested eager-loading criteria
- CVE-2026-79990GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/delete
- CVE-2026-79989Arbitrary user password reset leading to administrator account takeover
- CVE-2026-84802Craft CMS 5.7.0 before 5.10.12 Information Disclosure via AssetsController4.3