<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Craft CMS (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/craft-cms.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/craft-cms-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Craft CMS (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:37 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-47266 – Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, una...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47266</guid>
    <pubDate>Fri, 29 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47266</strong></p>
  <p>Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing submissions by posting a known or guessed submission ID to formie/submissions/save-submission. This vulnerability is fixed in 2.2.21 and 3.1.26.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45697 – Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, una...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45697</guid>
    <pubDate>Fri, 29 May 2026 20:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45697</strong></p>
  <p>Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). This vulnerability is fixed in 2.2.20 and 3.1.24.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31266 – Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31266</guid>
    <pubDate>Wed, 27 May 2026 15:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31266</strong></p>
  <p>Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44012 – Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44012</guid>
    <pubDate>Tue, 12 May 2026 21:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44012</strong></p>
  <p>Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() fetches an asset by ID and returns its filename and complete folder hierarchy (including volume handle, volume UID, folder names, folder UIDs, and folder URI paths) without checking whether the requesting user has viewAssets or viewPeerAssets permission on the asset’s volume. An…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44011 – Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44011</guid>
    <pubDate>Tue, 12 May 2026 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44011</strong></p>
  <p>Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an input-handling flaw in a Yii object creation path that let any authenticated user inject malicious configuration and execute arbitrary commands on the server. The request-controlled condition field layouts data is converted into a live FieldLayout object without a Component::cleans…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-479</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44010 – Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44010</guid>
    <pubDate>Tue, 12 May 2026 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44010</strong></p>
  <p>Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element resolver (src/gql/resolvers/elements/Address.php) performs no schema scope filtering on top-level queries. A GraphQL API token scoped to a single low-privilege user group can read every address in the system, including addresses belonging to users in groups the token has no authori…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32272 – Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32272</guid>
    <pubDate>Mon, 13 Apr 2026 21:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32272</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability exists where the ProductQuery::hasVariant and VariantQuery::hasProduct properties bypass the input sanitization blocklist added to ElementIndexesController in a prior security fix (GHSA-2453-mppf-46cj). The blocklist only strips top-level Yii2 Query properties such as where and o…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32271 – Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32271</guid>
    <pubDate>Mon, 13 Apr 2026 21:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32271</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an SQL injection vulnerability in the Commerce TotalRevenue widget which allows any authenticated control panel user to achieve remote code execution through a four-step exploitation chain. The attack exploits unsanitized widget settings interpolated into SQL expressions, comb…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33157 – Craft CMS is a content management system (CMS). From version 5.6.0 to before ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33157</guid>
    <pubDate>Tue, 24 Mar 2026 18:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33157</strong></p>
  <p>Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.13, a Remote Code Execution (RCE) vulnerability exists in Craft CMS, it can be exploited by any authenticated user with control panel access. This is a bypass of a previous fix. The existing patches add cleanseConfig() to assembleLayoutFromPost() and various FieldsController actions to strip Yii2 behavior/eve…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-470</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32268 – The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32268</guid>
    <pubDate>Wed, 18 Mar 2026 06:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32268</strong></p>
  <p>The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.1.1, unauthenticated users can view a list of buckets the plugin has access to. The `DefaultController->actionLoadContainerData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to see. Be…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32267 – Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32267</guid>
    <pubDate>Mon, 16 Mar 2026 20:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32267</strong></p>
  <p>Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their privileges to admin by abusing UsersController->actionImpersonateWithToken. This issue has been patched in versions 4.17.6 and 5.9.12.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32264 – Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32264</guid>
    <pubDate>Mon, 16 Mar 2026 20:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32264</strong></p>
  <p>Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, there is a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController. Craft control panel administrator permissions and allowAdminChanges must be enabled for this to work. This issue has been patched in versions 4.17.5 and…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-470</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32263 – Craft CMS is a content management system (CMS). From version 5.6.0 to before ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32263</guid>
    <pubDate>Mon, 16 Mar 2026 20:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32263</strong></p>
  <p>Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTypesController.php, the $settings array from parse_str is passed directly to Craft::configure() without Component::cleanseConfig(). This allows injecting Yii2 behavior/event handlers via "as" or "on" prefixed keys, the same attack vector as the original advisory. Craft control pan…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-470</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32261 – Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32261</guid>
    <pubDate>Mon, 16 Mar 2026 19:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32261</strong></p>
  <p>Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS, which will send GET or POST requests when certain events occur. From version 3.0.0 to before version 3.2.0, the Webhooks plugin renders user-supplied template content through Twig’s renderString() function without sandbox protection. This allows an authenticated user with access to the Craft control panel and permis…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31857 – Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31857</guid>
    <pubDate>Wed, 11 Mar 2026 18:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31857</strong></p>
  <p>Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The BaseElementSelectConditionRule::getElementIds() method passes user-controlled string input through renderObjectTemplate() -- an unsandboxed Twig rendering function with escaping disabled. Any authenticated Control Panel user (including non-a…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29174 – Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29174</guid>
    <pubDate>Tue, 10 Mar 2026 20:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29174</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in the inventory levels table data endpoint. The sort[0][direction] and sort[0][sortField] parameters are concatenated directly into an addOrderBy() clause without any validation or sanitization. An authenticated attacker with access to the Commerce Inventory section can inject arb…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29172 – Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29172</guid>
    <pubDate>Tue, 10 Mar 2026 20:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29172</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, Craft Commerce is vulnerable to SQL Injection in the purchasables table endpoint. The sort parameter is split by | and the first part (column name) is passed directly as an array key to orderBy() without whitelist validation. Yii2's query builder does NOT escape array keys, allowing an authenticated attacker to inje…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-28783 – Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-bet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28783</guid>
    <pubDate>Wed, 04 Mar 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-28783</strong></p>
  <p>Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerous PHP functions from being called via Twig non-Closure arrow functions. In order to be able to successfully execute this attack, you need to either have allowAdminChanges enabled on production, or a compromised admin account, or an account with acces…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28695 – Craft is a content management system (CMS). There is an authenticated admin RCE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28695</guid>
    <pubDate>Wed, 04 Mar 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28695</strong></p>
  <p>Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Template Injection using the create() Twig function combined with a Symfony Process gadget chain. The create() Twig function exposes Craft::createObject(), which allows instantiation of arbitrary PHP classes with constructor arguments. Combined with the bundled symfony/process depen…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25498 – Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 thro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25498</guid>
    <pubDate>Mon, 09 Feb 2026 20:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25498</strong></p>
  <p>Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a Remote Code Execution (RCE) vulnerability exists in Craft CMS where the assembleLayoutFromPost() function in src/services/Fields.php fails to sanitize user-supplied configuration data before passing it to Craft::createObject(). This allows authenticated administrators to inj…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-470</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25497 – Craft is a platform for creating digital experiences. In Craft versions from 4.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25497</guid>
    <pubDate>Mon, 09 Feb 2026 20:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25497</strong></p>
  <p>Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege Escalation vulnerability in Craft CMS’s GraphQL API that allows an authenticated user with write access to one asset volume to escalate their privileges and modify/transfer assets belonging to any other volume, including restricted or private volume…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-37071 – CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37071</guid>
    <pubDate>Tue, 03 Feb 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-37071</strong></p>
  <p>CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code execution by exploiting the plugin's vCard download functionality with a specially crafted request.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68454 – Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68454</guid>
    <pubDate>Mon, 05 Jan 2026 22:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68454</strong></p>
  <p>Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via Twig SSTI. For this to work, users must have administrator access to the Craft Control Panel, and allowAdminChanges must be enabled, which is against Craft CMS' recommendations for any non-dev environment. Alterna…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-52122 – Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52122</guid>
    <pubDate>Wed, 27 Aug 2025 15:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-52122</strong></p>
  <p>Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54417 – Craft is a platform for creating digital experiences. Versions 4.13.8 through 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54417</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54417</guid>
    <pubDate>Sat, 09 Aug 2025 02:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54417</strong></p>
  <p>Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass CVE-2025-23209: "Craft CMS has a potential RCE with a compromised security key". To exploit this vulnerability, the project must meet these requirements: have a compromised security key and create an arbitrary file in Craft's /storage/backups folder.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54417">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46731 – Craft is a content management system. Versions of Craft CMS on the 4.x branch pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46731</guid>
    <pubDate>Mon, 05 May 2025 20:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46731</strong></p>
  <p>Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13 or 5.6.15 to mitigate the issue.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52291 – Craft is a content management system (CMS). A vulnerability in CraftCMS allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52291</guid>
    <pubDate>Wed, 13 Nov 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52291</strong></p>
  <p>Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a double file:// scheme (e.g., file://file:////). This enables the attacker to specify sensitive folders as the file system, leading to potential file overwriting through malicious uploads, unauthorized access to sensitive files, and, under certain conditi…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-37843 – Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37843</guid>
    <pubDate>Tue, 25 Jun 2024 21:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-37843</strong></p>
  <p>Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36260 – An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36260</guid>
    <pubDate>Tue, 30 Jan 2024 09:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36260</strong></p>
  <p>An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings to Feed-Me Name and Feed-Me URL fields, due to saving a feed using an Asset element type with no volume selected. NOTE: this is not a report about code provided by the Craft CMS product; it is only a report about the Feed Me plugin. NOTE: a third-par…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-41892 – Craft CMS is a platform for creating digital experiences. This is a high-impact,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41892</guid>
    <pubDate>Wed, 13 Sep 2023 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-41892</strong></p>
  <p>Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30179 – CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30179</guid>
    <pubDate>Tue, 13 Jun 2023 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30179</strong></p>
  <p>CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution. NOTE: the vendor disputes this because only Administrators can add this Twig code, and (by design) Administrators are allowed to do that by default.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32679 – Craft CMS is an open source content management system. In affected versions of C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32679</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32679</guid>
    <pubDate>Fri, 19 May 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32679</strong></p>
  <p>Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension may lead to Remote Code Execution. If the name parameter value is not empty string('') in the View.php's doesTemplateExist() -> resolveTemplate() -> _resolveTemplateInternal() -> _resolveTemplate() function, it returns directly without extension verification, so that arbitrary e…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32679">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30130 – An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30130</guid>
    <pubDate>Fri, 12 May 2023 11:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30130</strong></p>
  <p>An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-37783 – All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37783</guid>
    <pubDate>Mon, 05 Dec 2022 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-37783</strong></p>
  <p>All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site Request Forgery attacks. The CRAFT_CSRF_TOKEN cookie discloses the password hash in without encoding it whereas the correspo…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-41749 – In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41749</guid>
    <pubDate>Sun, 12 Jun 2022 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-41749</strong></p>
  <p>In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29933 – Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29933</guid>
    <pubDate>Mon, 09 May 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29933</strong></p>
  <p>Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the password reset functionality. Specifically, the attacker must send X-Forwarded-Host to the /index.php?p=admin/actions/users/send-password-reset-email URI. NOTE: the…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41824 – Craft CMS before 3.7.14 allows CSV injection.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41824</guid>
    <pubDate>Thu, 30 Sep 2021 00:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41824</strong></p>
  <p>Craft CMS before 3.7.14 allows CSV injection.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1236</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-27903 – An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a pote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27903</guid>
    <pubDate>Wed, 30 Jun 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-27903</strong></p>
  <p>An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-13485 – The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13485</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13485</guid>
    <pubDate>Mon, 25 May 2020 23:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-13485</strong></p>
  <p>The Knock Knock plugin before 1.2.8 for Craft CMS allows IP Whitelist bypass via an X-Forwarded-For HTTP header.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-697</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13485">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-13458 – An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13458</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13458</guid>
    <pubDate>Mon, 25 May 2020 17:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-13458</strong></p>
  <p>An issue was discovered in the Image Resizer plugin before 2.0.9 for Craft CMS. There are CSRF issues with the log-clear controller action.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13458">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-12790 – In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-12790</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-12790</guid>
    <pubDate>Mon, 11 May 2020 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-12790</strong></p>
  <p>In the SEOmatic plugin before 3.2.49 for Craft CMS, helpers/DynamicMeta.php does not properly sanitize the URL. This leads to Server-Side Template Injection and credentials disclosure via a crafted Twig template after a semicolon.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-12790">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-9757 – The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-9757</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-9757</guid>
    <pubDate>Wed, 04 Mar 2020 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-9757</strong></p>
  <p>The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-9757">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2019-15929 – In Craft CMS through 3.1.7, the elevated session password prompt was not being r...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-15929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-15929</guid>
    <pubDate>Thu, 24 Oct 2019 16:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2019-15929</strong></p>
  <p>In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-15929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-20465 – Craft CMS through 3.0.34 allows remote authenticated administrators to read sens...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-20465</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-20465</guid>
    <pubDate>Tue, 25 Dec 2018 23:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-20465</strong></p>
  <p>Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes a cleartext username and password to be displayed in a URI field.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-20465">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-14716 – A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-14716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-14716</guid>
    <pubDate>Mon, 06 Aug 2018 20:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-14716</strong></p>
  <p>A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-14716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-3814 – Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by usin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-3814</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-3814</guid>
    <pubDate>Mon, 01 Jan 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-3814</strong></p>
  <p>Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option, because this allows a .jpg file to have embedded PHP code, and then be renamed to a .php extension.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-434</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-3814">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
