craftcms/cms vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-WG23-69C2-GJC8Criticalcraftcms/cms: Craft CMS: Passkey login accepts replayed WebAuthn assertionsGHSA-957R-QF9P-67XWMediumcraftcms/cms: Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contextsGHSA-596P-6JV8-775VMediumcraftcms/cms: Craft CMS: Authenticated leak of secret environment variablesGHSA-XXPX-F366-4XPQMediumcraftcms/cms: Craft CMS:Authorization bypass: view-only Categories user can modify category structure via structures/move-elementGHSA-RVMM-V933-JGXQMediumcraftcms/cms: Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metricsGHSA-7HXC-F267-H5Q7Lowcraftcms/cms: Craft CMS: Incorrect path validation could potentially lead to path traversalGHSA-2RP4-X2J7-QMCCMediumcraftcms/cms: Craft CMS: Stored XSS in the control panel via unescaped draft nameGHSA-P8X7-9VFW-P7VCHighcraftcms/cms: Craft CMS: Arbitrary user password reset leading to administrator account takeoverGHSA-F5WM-88JV-G5HXHighcraftcms/cms: Craft CMS: Authenticated RCE through Twig sandbox escapeCVE-2026-14793Mediumcraftcms/cms: Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global SetsGHSA-265M-7826-WJQMHighcraftcms/cms: Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypassCVE-2026-56382Highcraftcms/cms: Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreviewCVE-2026-56394Lowcraftcms/cms: Craft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file readCVE-2026-55794Highcraftcms/cms: Craft CMS: Potential authenticated Remote Code Execution via referrer redirectCVE-2026-55793Mediumcraftcms/cms: Craft CMS: Stored XSS via Structure entry title in table viewCVE-2026-55792Mediumcraftcms/cms: Craft CMS: Sensitive File Disclosure / Server-Side File ReadCVE-2026-55790Highcraftcms/cms: Craft CMS: DOM XSS via GitHub issue title in CraftSupport widgetCVE-2026-56384Mediumcraftcms/cms: Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permissionCVE-2026-50282Highcraftcms/cms: Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced MovesCVE-2026-50281Highcraftcms/cms: Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elementsCVE-2026-50284Highcraftcms/cms: Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assetsCVE-2026-50283Mediumcraftcms/cms: Craft CMS: Unauthorized Deletion of Source Assets During File ReplacementCVE-2026-50280Mediumcraftcms/cms: Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save checkCVE-2026-50279Highcraftcms/cms: Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gapCVE-2026-55791Criticalcraftcms/cms: Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs

Stop the waste.
Protect your environment with Kodem.