craftcms/cms vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-28782Mediumcraftcms/cms: Craft CMS has Permission Bypass and IDOR in Duplicate Entry ActionCVE-2026-28783Mediumcraftcms/cms: Craft CMS has Twig Function Blocklist BypassCVE-2026-28781Mediumcraftcms/cms: Craft CMS: Entries Authorship Spoofing via Mass AssignmentCVE-2026-28697Criticalcraftcms/cms: Craft CMS Vulnerable to Authenticated RCE via "craft.app.fs.write()" in Twig TemplatesCVE-2026-56393Lowcraftcms/cms: Craft CMS Vulnerable to Stored XSS in Settings Names and Field OptionsCVE-2026-28696Highcraftcms/cms: Craft CMS has IDOR via GraphQL @parseRefsCVE-2026-28695Mediumcraftcms/cms: Craft CMS Vulnerable to Authenticated RCE via Twig SSTI - create() function + Symfony Process gadgetCVE-2026-56383Lowcraftcms/cms: Craft CMS has Stored XSS in Table Field in its "Row Heading" Column TypeCVE-2026-27129Mediumcraftcms/cms: Craft CMS: Cloud Metadata SSRF Protection Bypass via IPv6 ResolutionCVE-2026-27128Mediumcraftcms/cms: Craft CMS Race condition in Token Service potentially allows for token usage greater than the token limitCVE-2026-27127Highcraftcms/cms: Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS RebindingCVE-2026-27126Mediumcraftcms/cms: Craft CMS has Stored XSS in Table Field via "HTML" Column TypeCVE-2026-25498Highcraftcms/cms: Craft CMS Vulnerable to potential authenticated Remote Code Execution via malicious attached BehaviorCVE-2026-25497Highcraftcms/cms: Craft CMS: GraphQL Asset Mutation Privilege EscalationCVE-2026-25496Mediumcraftcms/cms: Craft CMS Vulnerable to Stored XSS in Number Prefix & Suffix FieldsCVE-2026-25495Highcraftcms/cms: Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`CVE-2026-25494Mediumcraftcms/cms: Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via Alternative IP NotationCVE-2026-25493Mediumcraftcms/cms: Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via HTTP RedirectCVE-2026-25491Lowcraftcms/cms: Craft CMS Vulnerable to Stored XSS in Entry Types NameCVE-2025-68455Highcraftcms/cms: Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached BehaviorCVE-2025-68456Highcraftcms/cms: Unauthenticated Craft CMS users can trigger a database backupCVE-2025-68454Mediumcraftcms/cms: Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTICVE-2025-68437Mediumcraftcms/cms: Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload MutationCVE-2025-68436Mediumcraftcms/cms: Craft CMS vulnerable to potential information disclosure via unchecked asset relocationCVE-2025-57811Mediumcraftcms/cms: Craft CMS Potential Remote Code Execution via Twig SSTI

Stop the waste.
Protect your environment with Kodem.