craftcms/cms vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-44012Highcraftcms/cms: Craft CMS's Missing Volume Permission Check in AssetsController::actionShowInFolder Allows Information DisclosureCVE-2026-44011Highcraftcms/cms: Craft CMS has Potential Authenticated Remote Code Execution via Malicious Attached BehaviorCVE-2026-44010Highcraftcms/cms: Craft CMS's Missing Authorization in GraphQL Address Resolver Allows Cross-Scope PII DisclosureCVE-2026-41130Mediumcraftcms/cms: Craft CMS has a host header injection leading to SSRF via resource-js endpointCVE-2026-41129Mediumcraftcms/cms: Server-Side Request Forgery (SSRF) in Craft CMS with Asset Uploads MutationsCVE-2026-41128Mediumcraftcms/cms: Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions ActionCVE-2026-56385Lowcraftcms/cms: Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadataCVE-2026-33162Mediumcraftcms/cms: Craft CMS has an authorization bypass which allows any control panel user to move entries without permissionsCVE-2026-33161Lowcraftcms/cms: Craft CMS' anonymous "assets/image-editor" calls return private asset editor metadata to unauthorized usersCVE-2026-33160Lowcraftcms/cms: Craft CMS may expose private assets through anonymous "generate transform" calls via transform URLCVE-2026-33159Mediumcraftcms/cms: Craft CMS: Unauthenticated Users Can Perform Restricted Project Config Sync OperationsCVE-2026-33158Mediumcraftcms/cms: Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)CVE-2026-33157Highcraftcms/cms: Craft CMS is Vulnerable to Authenticated Remote Code Execution via Malicious Attached BehaviorCVE-2026-33051Mediumcraftcms/cms: Craft CMS Vulnerable to Stored XSS in Revision Context MenuCVE-2026-32267Highcraftcms/cms: Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()CVE-2026-32264Highcraftcms/cms: Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsControllerCVE-2026-32263Highcraftcms/cms: Craft CMS vulnerable to behavior injection RCE via EntryTypesControllerCVE-2026-32262Mediumcraftcms/cms: Craft CMS has a Path Traversal Vulnerability in AssetsControllerCVE-2026-56381Lowcraftcms/cms: Craft CMS Vulnerable to Stored XSS via User Group Name in User Permissions PageCVE-2026-31857Highcraftcms/cms: CraftCMS has an RCE vulnerability via relational conditionals in the control panelCVE-2026-31858Highcraftcms/cms: CraftCMS's `ElementSearchController` Affected by Blind SQL InjectionCVE-2026-31859Mediumcraftcms/cms: CraftCMS vulnerable to reflective XSS via incomplete return URL sanitizationCVE-2026-29113Lowcraftcms/cms: Craft CMS has a potential information disclosure vulnerability in preview tokensCVE-2026-29069Highcraftcms/cms: Craft CMS has unauthenticated activation email trigger with potential user enumerationCVE-2026-28784Mediumcraftcms/cms: Craft CMS has potential authenticated Remote Code Execution via Twig SSTI

Stop the waste.
Protect your environment with Kodem.