<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Craft CMS</title>
  <link>https://cvedaily.com/pages/tags/craft-cms.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/craft-cms.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Craft CMS</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:37 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-47266 – Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, una...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-47266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-47266</guid>
    <pubDate>Fri, 29 May 2026 20:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-47266</strong></p>
  <p>Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing submissions by posting a known or guessed submission ID to formie/submissions/save-submission. This vulnerability is fixed in 2.2.21 and 3.1.26.</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-45697 – Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, una...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-45697</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-45697</guid>
    <pubDate>Fri, 29 May 2026 20:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-45697</strong></p>
  <p>Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default value → Custom) that were evaluated as Twig during submission handling, which could lead to serious compromise of the Craft site (depending on template/sandbox behavior). This vulnerability is fixed in 2.2.20 and 3.1.24.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45697">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31266 – Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31266</guid>
    <pubDate>Wed, 27 May 2026 15:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31266</strong></p>
  <p>Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44012 – Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44012</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44012</guid>
    <pubDate>Tue, 12 May 2026 21:16:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44012</strong></p>
  <p>Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() fetches an asset by ID and returns its filename and complete folder hierarchy (including volume handle, volume UID, folder names, folder UIDs, and folder URI paths) without checking whether the requesting user has viewAssets or viewPeerAssets permission on the asset’s volume. An…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44012">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44011 – Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44011</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44011</guid>
    <pubDate>Tue, 12 May 2026 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44011</strong></p>
  <p>Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, Craft CMS which contains an input-handling flaw in a Yii object creation path that let any authenticated user inject malicious configuration and execute arbitrary commands on the server. The request-controlled condition field layouts data is converted into a live FieldLayout object without a Component::cleans…</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-479</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44011">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-44010 – Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-44010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-44010</guid>
    <pubDate>Tue, 12 May 2026 21:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-44010</strong></p>
  <p>Craft CMS is a content management system (CMS). From 4.0.0 to before 4.17.12 and 5.9.18, the GraphQL Address element resolver (src/gql/resolvers/elements/Address.php) performs no schema scope filtering on top-level queries. A GraphQL API token scoped to a single low-privilege user group can read every address in the system, including addresses belonging to users in groups the token has no authori…</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41130 – Craft CMS is a content management system (CMS). In versions on the 4.x branch th...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41130</guid>
    <pubDate>Wed, 22 Apr 2026 00:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41130</strong></p>
  <p>Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources.  When `trustedHosts` is not explicitly restricted (default configuration), the application trusts the client-supplied Host header. This allows an attacker to con…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41129 – Craft CMS is a content management system (CMS). Versions on the 4.x branch throu...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41129</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41129</guid>
    <pubDate>Wed, 22 Apr 2026 00:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41129</strong></p>
  <p>Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema: "Edit assets in the <VolumeName> volume" and "Create assets in the <VolumeName> volume." Versions 4.17.9 and 5.9.15 patch the issue.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41129">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-41128 – Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-41128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-41128</guid>
    <pubDate>Wed, 22 Apr 2026 00:16:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-41128</strong></p>
  <p>Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group authorization for additions, it performs no equivalent authorization check for removals, so submitting an empty `groups` value removes all…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32272 – Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32272</guid>
    <pubDate>Mon, 13 Apr 2026 21:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32272</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. In versions 5.0.0 through 5.5.4, an SQL injection vulnerability exists where the ProductQuery::hasVariant and VariantQuery::hasProduct properties bypass the input sanitization blocklist added to ElementIndexesController in a prior security fix (GHSA-2453-mppf-46cj). The blocklist only strips top-level Yii2 Query properties such as where and o…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32271 – Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32271</guid>
    <pubDate>Mon, 13 Apr 2026 21:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32271</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, there is an SQL injection vulnerability in the Commerce TotalRevenue widget which allows any authenticated control panel user to achieve remote code execution through a four-step exploitation chain. The attack exploits unsanitized widget settings interpolated into SQL expressions, comb…</p>
  <p><strong>CVSS:</strong> 7.7 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-32270 – Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32270</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32270</guid>
    <pubDate>Mon, 13 Apr 2026 20:16:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-32270</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. In versions 4.0.0 through 4.10.2 and 5.0.0 through 5.5.4, the PaymentsController::actionPay discloses some order data to unauthenticated users when an order number is provided and the email check fails during an anonymous payment. The JSON error response includes the serialized order object (order), which contains some sensitive fields such a…</p>
  <p><strong>CVSS:</strong> 1.7 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32270">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33162 – Craft CMS is a content management system (CMS). From version 5.3.0 to before ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33162</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33162</guid>
    <pubDate>Tue, 24 Mar 2026 18:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33162</strong></p>
  <p>Craft CMS is a content management system (CMS). From version 5.3.0 to before version 5.9.14, an authenticated control panel user with only accessCp can move entries across sections via POST /actions/entries/move-to-section, even when they do not have saveEntries:{sectionUid} permission for either source or destination section. This issue has been patched in version 5.9.14.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33162">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33161 – Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33161</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33161</guid>
    <pubDate>Tue, 24 Mar 2026 18:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33161</strong></p>
  <p>Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can call assets/image-editor with the ID of a private asset they cannot view and still receive editor response data, including focalPoint. The endpoint returns private editing metadata without per-asset authorizati…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33161">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33160 – Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33160</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33160</guid>
    <pubDate>Tue, 24 Mar 2026 18:16:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33160</strong></p>
  <p>Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, an unauthenticated user can call assets/generate-transform with a private assetId, receive a valid transform URL, and fetch transformed image bytes. The endpoint is anonymous and does not enforce per-asset authorization before returning the transform…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33160">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33159 – Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33159</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33159</guid>
    <pubDate>Tue, 24 Mar 2026 18:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33159</strong></p>
  <p>Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, guest users can access Config Sync updater index, obtain signed data, and execute state-changing Config Sync actions (regenerate-yaml, apply-yaml-changes) without authentication. This issue has been patched in versions 4.17.8 and 5.9.14.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-306</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33159">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33158 – Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33158</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33158</guid>
    <pubDate>Tue, 24 Mar 2026 18:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33158</strong></p>
  <p>Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-RC1 to before version 5.9.14, a low-privileged authenticated user can read private asset content by calling assets/edit-image with an arbitrary assetId that they are not authorized to view. The endpoint returns image bytes (or a preview redirect) without enforcing a per-asset vie…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33158">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-33157 – Craft CMS is a content management system (CMS). From version 5.6.0 to before ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33157</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33157</guid>
    <pubDate>Tue, 24 Mar 2026 18:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-33157</strong></p>
  <p>Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.13, a Remote Code Execution (RCE) vulnerability exists in Craft CMS, it can be exploited by any authenticated user with control panel access. This is a bypass of a previous fix. The existing patches add cleanseConfig() to assembleLayoutFromPost() and various FieldsController actions to strip Yii2 behavior/eve…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-470</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33157">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27131 – The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27131</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27131</guid>
    <pubDate>Mon, 23 Mar 2026 20:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27131</strong></p>
  <p>The Sprig Plugin for Craft CMS is a reactive Twig component framework for Craft CMS. Starting in version 2.0.0 and prior to versions 2.15.2 and 3.15.2, admin users, and users with explicit permission to access the Sprig Playground, could potentially expose the security key, credentials, and other sensitive configuration data, in addition to running the `hashData()` signing function. This issue wa…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27131">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-33051 – Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33051</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33051</guid>
    <pubDate>Fri, 20 Mar 2026 06:16:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33051</strong></p>
  <p>Craft CMS is a content management system (CMS). In versions 5.9.0-beta.1 through 5.9.10, the revision/draft context menu in the element editor renders the creator’s fullName as raw HTML due to the use of Template::raw() combined with Craft::t() string interpolation. A low-privileged control panel user (e.g., Author) can set their fullName to an XSS payload via the profile editor, then create an e…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33051">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32268 – The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32268</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32268</guid>
    <pubDate>Wed, 18 Mar 2026 06:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32268</strong></p>
  <p>The Azure Blob Storage for Craft CMS plugin provides an Azure Blob Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.1.1, unauthenticated users can view a list of buckets the plugin has access to. The `DefaultController->actionLoadContainerData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to see. Be…</p>
  <p><strong>CVSS:</strong> 8.7 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32268">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-32266 – The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32266</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32266</guid>
    <pubDate>Wed, 18 Mar 2026 04:17:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-32266</strong></p>
  <p>The Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.2.1, the `DefaultController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to see. Users should update to version 2.2.1 of the plugin to mitigate the issue.</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32266">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32265 – The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32265</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32265</guid>
    <pubDate>Wed, 18 Mar 2026 04:17:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32265</strong></p>
  <p>The Amazon S3 for Craft CMS plugin provides an Amazon S3 integration for Craft CMS. In versions 2.0.2 through 2.2.4, unauthenticated users can view a list of buckets the plugin has access to. The `BucketsController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to see. Users should update to version 2.2.5…</p>
  <p><strong>CVSS:</strong> 6.9 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32265">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-32267 – Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32267</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32267</guid>
    <pubDate>Mon, 16 Mar 2026 20:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-32267</strong></p>
  <p>Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an unauthenticated user who has been sent a shared URL) can escalate their privileges to admin by abusing UsersController->actionImpersonateWithToken. This issue has been patched in versions 4.17.6 and 5.9.12.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32267">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32264 – Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32264</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32264</guid>
    <pubDate>Mon, 16 Mar 2026 20:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32264</strong></p>
  <p>Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, there is a Behavior injection RCE vulnerability in ElementIndexesController and FieldsController. Craft control panel administrator permissions and allowAdminChanges must be enabled for this to work. This issue has been patched in versions 4.17.5 and…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-470</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32264">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32263 – Craft CMS is a content management system (CMS). From version 5.6.0 to before ver...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32263</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32263</guid>
    <pubDate>Mon, 16 Mar 2026 20:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32263</strong></p>
  <p>Craft CMS is a content management system (CMS). From version 5.6.0 to before version 5.9.11, in src/controllers/EntryTypesController.php, the $settings array from parse_str is passed directly to Craft::configure() without Component::cleanseConfig(). This allows injecting Yii2 behavior/event handlers via "as" or "on" prefixed keys, the same attack vector as the original advisory. Craft control pan…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-470</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32263">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-32262 – Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32262</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32262</guid>
    <pubDate>Mon, 16 Mar 2026 20:16:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-32262</strong></p>
  <p>Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.5 and from version 5.0.0-RC1 to before version 5.9.11, the AssetsController->replaceFile() method has a targetFilename body parameter that is used unsanitized in a deleteFile() call before Assets::prepareAssetName() is applied on save. This allows an authenticated user with replaceFiles permission to del…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32262">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-32261 – Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-32261</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-32261</guid>
    <pubDate>Mon, 16 Mar 2026 19:16:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-32261</strong></p>
  <p>Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS, which will send GET or POST requests when certain events occur. From version 3.0.0 to before version 3.2.0, the Webhooks plugin renders user-supplied template content through Twig’s renderString() function without sandbox protection. This allows an authenticated user with access to the Craft control panel and permis…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-32261">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-31867 – Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31867</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31867</guid>
    <pubDate>Wed, 11 Mar 2026 18:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-31867</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.11.0 and 5.6.0, An Insecure Direct Object Reference (IDOR) vulnerability exists in Craft Commerce’s cart functionality that allows users to hijack any shopping cart by knowing or guessing its 32-character number. The CartController accepts a user-supplied number parameter to load and modify shopping carts. No ownership validation i…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31867">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-31859 – Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31859</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31859</guid>
    <pubDate>Wed, 11 Mar 2026 18:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-31859</strong></p>
  <p>Craft is a content management system (CMS). The fix for CVE-2025-35939 in craftcms/cms introduced a strip_tags() call in src/web/User.php to sanitize return URLs before they are stored in the session. However, strip_tags() only removes HTML tags (angle brackets) -- it does not inspect or filter URL schemes. Payloads like javascript:alert(document.cookie) contain no HTML tags and pass through stri…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31859">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-31857 – Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-31857</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-31857</guid>
    <pubDate>Wed, 11 Mar 2026 18:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-31857</strong></p>
  <p>Craft is a content management system (CMS). Prior to 5.9.9 and 4.17.4, a Remote Code Execution vulnerability exists in the Craft CMS 5 conditions system. The BaseElementSelectConditionRule::getElementIds() method passes user-controlled string input through renderObjectTemplate() -- an unsandboxed Twig rendering function with escaping disabled. Any authenticated Control Panel user (including non-a…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-31857">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-29177 – Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29177</guid>
    <pubDate>Tue, 10 Mar 2026 20:16:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-29177</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Craft Commerce Order details. Malicious JavaScript can be injected via the Shipping Method Name, Order Reference, or Site Name. When a user opens the order details slideout via a double-click on the order index page, the injected payload executes. This…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-29176 – Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, A stored ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29176</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29176</guid>
    <pubDate>Tue, 10 Mar 2026 20:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-29176</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, A stored XSS vulnerability exists in the Commerce Settings - Inventory Locations page. The Name field is rendered without proper HTML escaping, allowing an attacker to execute arbitrary JavaScript. This XSS triggers when an administrator (or user with product editing permissions) creates or edits a variant product. This vulner…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29176">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-29175 – Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Stored XS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29175</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29175</guid>
    <pubDate>Tue, 10 Mar 2026 20:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-29175</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Stored XSS vulnerabilities exist in the Commerce Inventory page. The Product Title, Variant Title, and Variant SKU fields are rendered without proper HTML escaping, allowing an attacker to execute arbitrary JavaScript when any user (including administrators) views the inventory management page. This vulnerability is fixed in 5…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29175">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29174 – Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Com...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29174</guid>
    <pubDate>Tue, 10 Mar 2026 20:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29174</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. Prior to 5.5.3, Craft Commerce is vulnerable to SQL Injection in the inventory levels table data endpoint. The sort[0][direction] and sort[0][sortField] parameters are concatenated directly into an addOrderBy() clause without any validation or sanitization. An authenticated attacker with access to the Commerce Inventory section can inject arb…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-29173 – Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29173</guid>
    <pubDate>Tue, 10 Mar 2026 20:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-29173</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, a stored XSS vulnerability exists when a user tries to update the Order Status from the Commerce Orders Table. The Order Status Name is rendered without proper escaping, allowing script execution to occur. This vulnerability is fixed in 4.10.2 and 5.5.3.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-29172 – Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29172</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29172</guid>
    <pubDate>Tue, 10 Mar 2026 20:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-29172</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. Prior to 4.10.2 and 5.5.3, Craft Commerce is vulnerable to SQL Injection in the purchasables table endpoint. The sort parameter is split by | and the first part (column name) is passed directly as an array key to orderBy() without whitelist validation. Yii2's query builder does NOT escape array keys, allowing an authenticated attacker to inje…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29172">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-29113 – Craft is a content management system (CMS). Prior to 4.17.4 and 5.9.7, Craft CMS...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-29113</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-29113</guid>
    <pubDate>Tue, 10 Mar 2026 20:16:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-29113</strong></p>
  <p>Craft is a content management system (CMS). Prior to 4.17.4 and 5.9.7, Craft CMS has a CSRF issue in the preview token endpoint at /actions/preview/create-token. The endpoint accepts an attacker-supplied previewToken. Because the action does not require POST and does not enforce a CSRF token, an attacker can force a logged-in victim editor to mint a preview token chosen by the attacker. That toke…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-29113">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2026-28783 – Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-bet...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28783</guid>
    <pubDate>Wed, 04 Mar 2026 17:16:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2026-28783</strong></p>
  <p>Craft is a content management system (CMS). Prior to 5.9.0-beta.1 and 4.17.0-beta.1, Craft CMS implements a blocklist to prevent potentially dangerous PHP functions from being called via Twig non-Closure arrow functions. In order to be able to successfully execute this attack, you need to either have allowAdminChanges enabled on production, or a compromised admin account, or an account with acces…</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-28695 – Craft is a content management system (CMS). There is an authenticated admin RCE ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-28695</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-28695</guid>
    <pubDate>Wed, 04 Mar 2026 17:16:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-28695</strong></p>
  <p>Craft is a content management system (CMS). There is an authenticated admin RCE in Craft CMS 5.8.21 via Server-Side Template Injection using the create() Twig function combined with a Symfony Process gadget chain. The create() Twig function exposes Craft::createObject(), which allows instantiation of arbitrary PHP classes with constructor arguments. Combined with the bundled symfony/process depen…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28695">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27129 – Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27129</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27129</guid>
    <pubDate>Tue, 24 Feb 2026 03:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27129</strong></p>
  <p>Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation uses `gethostbyname()`, which only resolves IPv4 addresses. When a hostname has only AAAA (IPv6) records, the function returns the hostname string itself, causing the blocklist comparison to always fail and completely bypassing S…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27129">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27128 – Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27128</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27128</guid>
    <pubDate>Tue, 24 Feb 2026 03:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27128</strong></p>
  <p>Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, a Time-of-Check-Time-of-Use (TOCTOU) race condition exists in Craft CMS’s token validation service for tokens that explicitly set a limited usage. The `getTokenRoute()` method reads a token’s usage count, checks if it’s within limits, then updates the database in separate non-atomic ope…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27128">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-27127 – Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-27127</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-27127</guid>
    <pubDate>Tue, 24 Feb 2026 03:16:02 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-27127</strong></p>
  <p>Craft is a content management system (CMS). In versions 4.5.0-RC1 through 4.16.18 and 5.0.0-RC1 through 5.8.22, the SSRF validation in Craft CMS’s GraphQL Asset mutation performs DNS resolution separately from the HTTP request. This Time-of-Check-Time-of-Use (TOCTOU) vulnerability enables DNS rebinding attacks, where an attacker’s DNS server returns different IP addresses for validation compared…</p>
  <p><strong>CVSS:</strong> 6.3 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27127">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-26188 – Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building too...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-26188</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-26188</guid>
    <pubDate>Thu, 12 Feb 2026 23:16:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-26188</strong></p>
  <p>Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. An authenticated, low-privilege user (able to create/edit forms) can inject arbitrary HTML/JS into the Craft Control Panel (CP) builder and integrations views. User-controlled form labels and integration metadata are rendered with dangerouslySetInnerHTML without sanitization, leading to stored XSS that executes whe…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-26188">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25498 – Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 thro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25498</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25498</guid>
    <pubDate>Mon, 09 Feb 2026 20:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25498</strong></p>
  <p>Craft is a platform for creating digital experiences. In versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, a Remote Code Execution (RCE) vulnerability exists in Craft CMS where the assembleLayoutFromPost() function in src/services/Fields.php fails to sanitize user-supplied configuration data before passing it to Craft::createObject(). This allows authenticated administrators to inj…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-470</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25498">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-25497 – Craft is a platform for creating digital experiences. In Craft versions from 4.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25497</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25497</guid>
    <pubDate>Mon, 09 Feb 2026 20:15:58 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-25497</strong></p>
  <p>Craft is a platform for creating digital experiences. In Craft versions from 4.0.0-RC1 to before 4.17.0-beta.1 and 5.9.0-beta.1, there is a Privilege Escalation vulnerability in Craft CMS’s GraphQL API that allows an authenticated user with write access to one asset volume to escalate their privileges and modify/transfer assets belonging to any other volume, including restricted or private volume…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-639</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25497">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25492 – Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25492</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25492</guid>
    <pubDate>Mon, 09 Feb 2026 20:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25492</strong></p>
  <p>Craft CMS is a content management system. In Craft versions 3.5.0 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the save_images_Asset GraphQL mutation can be abused to fetch internal URLs by providing a domain name that resolves to an internal IP address, bypassing hostname validation. When a non-image file extension such as .txt is allowed, downstream image validation is bypassed, which can allo…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25492">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-37071 – CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-37071</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-37071</guid>
    <pubDate>Tue, 03 Feb 2026 22:16:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-37071</strong></p>
  <p>CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code execution by exploiting the plugin's vCard download functionality with a specially crafted request.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-37071">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25522 – Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25522</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25522</guid>
    <pubDate>Tue, 03 Feb 2026 19:16:27 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25522</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Shipping Zone (Name & Description) fields in the Store Management section are not properly sanitized before being displayed in the ad…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25522">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25490 – Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25490</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25490</guid>
    <pubDate>Tue, 03 Feb 2026 19:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25490</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the 'Address Line 1' field in Inventory Locations is not properly sanitized before being displayed in the admin panel. This issue has bee…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25490">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25489 – Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25489</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25489</guid>
    <pubDate>Tue, 03 Feb 2026 19:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25489</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Name & Description fields in Tax Zones are not properly sanitized before being displayed in the admin panel. This issue has been patc…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25489">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25488 – Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25488</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25488</guid>
    <pubDate>Tue, 03 Feb 2026 19:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25488</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Tax Categories (Name & Description) fields in the Store Management section are not properly sanitized before being displayed in the a…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25488">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25487 – Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25487</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25487</guid>
    <pubDate>Tue, 03 Feb 2026 19:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25487</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator's browser. This occurs because the Tax Rates 'Name' field in the Store Management section is not properly sanitized before being displayed in the admin panel. This issu…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25487">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25486 – Craft Commerce is an ecommerce platform for Craft CMS. From version 5.0.0 to 5.5...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25486</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25486</guid>
    <pubDate>Tue, 03 Feb 2026 19:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25486</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. From version 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Shipping Methods Name field in the Store Management section is not properly sanitized before being displayed in the admin panel. This issue has been patched in versio…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25486">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25485 – Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25485</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25485</guid>
    <pubDate>Tue, 03 Feb 2026 19:16:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25485</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability in Craft Commerce allows attackers to execute malicious JavaScript in an administrator’s browser. This occurs because the Shipping Categories (Name & Description) fields in the Store Management section are not properly sanitized before being displayed in…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25485">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25484 – Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25484</guid>
    <pubDate>Tue, 03 Feb 2026 19:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25484</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, there is a Stored XSS via Product Type names. The name is not sanitized when displayed in user permissions settings. The vulnerable input (source) is in Commerce (Product Type settings), but the sink is in CMS user permissions settings. This issue has been patched in versions 4.10.…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25483 – Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25483</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25483</guid>
    <pubDate>Tue, 03 Feb 2026 19:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25483</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored XSS vulnerability exists in Craft Commerce’s Order Status History Message. The message is rendered using the |md filter, which permits raw HTML, enabling malicious script execution. If a user has database backup utility permissions (which do not require an elevated session…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25483">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-25482 – Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-25482</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-25482</guid>
    <pubDate>Tue, 03 Feb 2026 19:16:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-25482</strong></p>
  <p>Craft Commerce is an ecommerce platform for Craft CMS. In versions from 4.0.0-RC1 to 4.10.0 and from 5.0.0 to 5.5.1, a stored DOM XSS vulnerability exists in the "Recent Orders" dashboard widget. The Order Status Name is rendered via JavaScript string concatenation without proper escaping, allowing script execution when any admin visits the dashboard. This issue has been patched in versions 4.10.…</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25482">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-68454 – Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68454</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68454</guid>
    <pubDate>Mon, 05 Jan 2026 22:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-68454</strong></p>
  <p>Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via Twig SSTI. For this to work, users must have administrator access to the Craft Control Panel, and allowAdminChanges must be enabled, which is against Craft CMS' recommendations for any non-dev environment. Alterna…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68454">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-68437 – Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 thro...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68437</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68437</guid>
    <pubDate>Mon, 05 Jan 2026 22:15:52 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-68437</strong></p>
  <p>Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, the Craft CMS GraphQL `save_<VolumeName>_Asset` mutation is vulnerable to Server-Side Request Forgery (SSRF). This vulnerability arises because the `_file` input, specifically its `url` parameter, allows the server to fetch content from arbitrary remote locations without prope…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-918</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68437">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-52122 – Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-52122</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-52122</guid>
    <pubDate>Wed, 27 Aug 2025 15:15:39 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-52122</strong></p>
  <p>Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-52122">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-54417 – Craft is a platform for creating digital experiences. Versions 4.13.8 through 4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-54417</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-54417</guid>
    <pubDate>Sat, 09 Aug 2025 02:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-54417</strong></p>
  <p>Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass CVE-2025-23209: "Craft CMS has a potential RCE with a compromised security key". To exploit this vulnerability, the project must meet these requirements: have a compromised security key and create an arbitrary file in Craft's /storage/backups folder.…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-54417">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-35939 – Craft CMS stores arbitrary content provided by unauthenticated users in session ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-35939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-35939</guid>
    <pubDate>Wed, 07 May 2025 23:15:54 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-35939</strong></p>
  <p>Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require authentication to the login page and generates a session file on the server at '/var/lib/php/sessions'. Such session files are named 'sess_[session_value]', where '[session_value]'…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-472</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-35939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-46731 – Craft is a content management system. Versions of Craft CMS on the 4.x branch pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-46731</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-46731</guid>
    <pubDate>Mon, 05 May 2025 20:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-46731</strong></p>
  <p>Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13 or 5.6.15 to mitigate the issue.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-46731">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-32427 – Formie is a Craft CMS plugin for creating forms. Prior to 2.1.44, when importing...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32427</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32427</guid>
    <pubDate>Fri, 11 Apr 2025 14:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-32427</strong></p>
  <p>Formie is a Craft CMS plugin for creating forms. Prior to 2.1.44, when importing a form from JSON, if the field label or handle contained malicious content, the output wasn't correctly escaped when viewing a preview of what was to be imported. As imports are undertaking primarily by users who have themselves exported the form from one environment to another, and would require direct manipulation…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32427">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-32426 – Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-32426</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-32426</guid>
    <pubDate>Fri, 11 Apr 2025 14:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-32426</strong></p>
  <p>Formie is a Craft CMS plugin for creating forms. Prior to version 2.1.44, it is possible to inject malicious code into the HTML content of an email notification, which is then rendered on the preview. There is no issue when rendering the email via normal means (a delivered email). This would require access to the form's email notification settings. This has been fixed in Formie 2.1.44.</p>
  <p><strong>CVSS:</strong> 4.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-32426">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-52291 – Craft is a content management system (CMS). A vulnerability in CraftCMS allows a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-52291</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-52291</guid>
    <pubDate>Wed, 13 Nov 2024 17:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-52291</strong></p>
  <p>Craft is a content management system (CMS). A vulnerability in CraftCMS allows an attacker to bypass local file system validation by utilizing a double file:// scheme (e.g., file://file:////). This enables the attacker to specify sensitive folders as the file system, leading to potential file overwriting through malicious uploads, unauthorized access to sensitive files, and, under certain conditi…</p>
  <p><strong>CVSS:</strong> 8.4 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-52291">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-45406 – Craft is a content management system (CMS). Craft CMS 5 stored XSS can be trigge...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-45406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-45406</guid>
    <pubDate>Mon, 09 Sep 2024 17:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-45406</strong></p>
  <p>Craft is a content management system (CMS). Craft CMS 5 stored XSS can be triggered by the breadcrumb list and title fields with user input.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-45406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-41800 – Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tok...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41800</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41800</guid>
    <pubDate>Thu, 25 Jul 2024 17:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-41800</strong></p>
  <p>Craft is a content management system (CMS). Craft CMS 5 allows reuse of TOTP tokens multiple times within the validity period. An attacker is able to re-submit a valid TOTP token to establish an authenticated session. This requires that the attacker has knowledge of the victim's credentials. This has been patched in Craft 5.2.3.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41800">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-37843 – Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-37843</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-37843</guid>
    <pubDate>Tue, 25 Jun 2024 21:15:59 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-37843</strong></p>
  <p>Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-37843">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-5658 – The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5658</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5658</guid>
    <pubDate>Thu, 06 Jun 2024 11:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-5658</strong></p>
  <p>The CraftCMS plugin Two-Factor Authentication through 3.3.3 allows reuse of TOTP tokens multiple times within the validity period.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-303</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5658">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-5657 – The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-5657</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-5657</guid>
    <pubDate>Thu, 06 Jun 2024 11:15:49 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-5657</strong></p>
  <p>The CraftCMS plugin Two-Factor Authentication in versions 3.3.1, 3.3.2 and 3.3.3 discloses the password hash of the currently authenticated user after submitting a valid TOTP.</p>
  <p><strong>CVSS:</strong> 3.7 · <strong>CWE:</strong> CWE-499</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-5657">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-35191 – Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with acce...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-35191</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-35191</guid>
    <pubDate>Mon, 20 May 2024 21:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-35191</strong></p>
  <p>Formie is a Craft CMS plugin for creating forms. Prior to 2.1.6, users with access to a form's settings can include malicious Twig code into fields that support Twig. These might be the Submission Title or the Success Message. This code will then be executed upon creating a submission, or rendering the text.  This has been fixed in Formie 2.1.6.</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-1336</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-35191">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-36260 – An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows rem...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36260</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36260</guid>
    <pubDate>Tue, 30 Jan 2024 09:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-36260</strong></p>
  <p>An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS. It allows remote attackers to cause a denial of service (DoS) via crafted strings to Feed-Me Name and Feed-Me URL fields, due to saving a feed using an Asset element type with no volume selected. NOTE: this is not a report about code provided by the Craft CMS product; it is only a report about the Feed Me plugin. NOTE: a third-par…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36260">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-36259 – Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before versio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-36259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-36259</guid>
    <pubDate>Tue, 30 Jan 2024 09:15:47 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-36259</strong></p>
  <p>Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbitrary code during user creation.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-36259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-41892 – Craft CMS is a platform for creating digital experiences. This is a high-impact,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-41892</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-41892</guid>
    <pubDate>Wed, 13 Sep 2023 20:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-41892</strong></p>
  <p>Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-41892">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-33495 – Craft CMS through 4.4.9 is vulnerable to HTML Injection.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-33495</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-33495</guid>
    <pubDate>Tue, 20 Jun 2023 13:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-33495</strong></p>
  <p>Craft CMS through 4.4.9 is vulnerable to HTML Injection.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-33495">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30179 – CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30179</guid>
    <pubDate>Tue, 13 Jun 2023 17:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30179</strong></p>
  <p>CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Execution. NOTE: the vendor disputes this because only Administrators can add this Twig code, and (by design) Administrators are allowed to do that by default.</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30179">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-2817 – A post-authentication stored cross-site scripting vulnerability exists in Craft ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-2817</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-2817</guid>
    <pubDate>Fri, 26 May 2023 17:15:17 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-2817</strong></p>
  <p>A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-2817">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-32679 – Craft CMS is an open source content management system. In affected versions of C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-32679</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-32679</guid>
    <pubDate>Fri, 19 May 2023 20:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-32679</strong></p>
  <p>Craft CMS is an open source content management system. In affected versions of Craft CMS an unrestricted file extension may lead to Remote Code Execution. If the name parameter value is not empty string('') in the View.php's doesTemplateExist() -> resolveTemplate() -> _resolveTemplateInternal() -> _resolveTemplate() function, it returns directly without extension verification, so that arbitrary e…</p>
  <p><strong>CVSS:</strong> 7.2 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-32679">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-30130 – An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30130</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30130</guid>
    <pubDate>Fri, 12 May 2023 11:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-30130</strong></p>
  <p>An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30130">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-31144 – Craft CMS is a content management system. Starting in version 3.0.0 and prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-31144</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-31144</guid>
    <pubDate>Tue, 09 May 2023 16:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-31144</strong></p>
  <p>Craft CMS is a content management system. Starting in version 3.0.0 and prior to versions 3.8.4 and 4.4.4, a malformed title in the feed widget can deliver a cross-site scripting payload. This issue is fixed in version 3.8.4 and 4.4.4.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-31144">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-30177 – CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-30177</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-30177</guid>
    <pubDate>Tue, 25 Apr 2023 18:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-30177</strong></p>
  <p>CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-30177">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-37783 – All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37783</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37783</guid>
    <pubDate>Mon, 05 Dec 2022 21:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-37783</strong></p>
  <p>All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens. Craft CMS uses a cookie called CRAFT_CSRF_TOKEN and a HTML hidden field called CRAFT_CSRF_TOKEN to avoid Cross Site Request Forgery attacks. The CRAFT_CSRF_TOKEN cookie discloses the password hash in without encoding it whereas the correspo…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-522</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37783">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-37246 – Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37246</guid>
    <pubDate>Wed, 21 Sep 2022 15:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-37246</strong></p>
  <p>Craft CMS 4.2.0.1 is affected by Cross Site Scripting (XSS) in the file src/web/assets/cp/src/js/BaseElementSelectInput.js and in specific on the line label: elementInfo.label.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-37251 – Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37251</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37251</guid>
    <pubDate>Fri, 16 Sep 2022 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-37251</strong></p>
  <p>Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via Drafts.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37251">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-37247 – Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37247</guid>
    <pubDate>Fri, 16 Sep 2022 22:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-37247</strong></p>
  <p>Craft CMS 4.2.0.1 is vulnerable to stored a cross-site scripting (XSS) via /admin/settings/fields page.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-37248 – Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37248</guid>
    <pubDate>Fri, 16 Sep 2022 16:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-37248</strong></p>
  <p>Craft CMS 4.2.0.1 is vulnerable to Cross Site Scripting (XSS) via src/helpers/Cp.php.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-37250 – Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myacc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37250</guid>
    <pubDate>Fri, 16 Sep 2022 15:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-37250</strong></p>
  <p>Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-41750 – A cross-site scripting (XSS) vulnerability in the SEOmatic plugin 3.4.10 for Cra...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41750</guid>
    <pubDate>Sun, 12 Jun 2022 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-41750</strong></p>
  <p>A cross-site scripting (XSS) vulnerability in the SEOmatic plugin 3.4.10 for Craft CMS 3 allows remote attackers to inject arbitrary web script via a GET to /index.php?action=seomatic/file/seo-file-link with url parameter containing the base64 encoded URL of a malicious web page / file and fileName parameter containing an arbitrary filename with the intended content-type to be rendered in the use…</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-41749 – In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthen...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41749</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41749</guid>
    <pubDate>Sun, 12 Jun 2022 11:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-41749</strong></p>
  <p>In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41749">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-29933 – Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-29933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-29933</guid>
    <pubDate>Mon, 09 May 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-29933</strong></p>
  <p>Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the password reset functionality. Specifically, the attacker must send X-Forwarded-Host to the /index.php?p=admin/actions/users/send-password-reset-email URI. NOTE: the…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-640</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-29933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-28378 – Craft CMS before 3.7.29 allows XSS.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-28378</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-28378</guid>
    <pubDate>Sun, 03 Apr 2022 18:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-28378</strong></p>
  <p>Craft CMS before 3.7.29 allows XSS.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-28378">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-23409 – The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-23409</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-23409</guid>
    <pubDate>Mon, 31 Jan 2022 08:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-23409</strong></p>
  <p>The Logs plugin before 3.0.4 for Craft CMS allows remote attackers to read arbitrary files via input to actionStream in Controller.php.</p>
  <p><strong>CVSS:</strong> 4.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-23409">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-41824 – Craft CMS before 3.7.14 allows CSV injection.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-41824</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-41824</guid>
    <pubDate>Thu, 30 Sep 2021 00:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-41824</strong></p>
  <p>Craft CMS before 3.7.14 allows CSV injection.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-1236</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-41824">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2021-27903 – An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a pote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27903</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27903</guid>
    <pubDate>Wed, 30 Jun 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2021-27903</strong></p>
  <p>An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-862</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27903">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-27902 – An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a pote...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-27902</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-27902</guid>
    <pubDate>Wed, 30 Jun 2021 12:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-27902</strong></p>
  <p>An issue was discovered in Craft CMS before 3.6.0. In some circumstances, a potential XSS vulnerability existed in connection with front-end forms that accepted user uploads.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-27902">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-32470 – Craft CMS before 3.6.13 has an XSS vulnerability.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32470</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32470</guid>
    <pubDate>Fri, 07 May 2021 19:31:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-32470</strong></p>
  <p>Craft CMS before 3.6.13 has an XSS vulnerability.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32470">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-19626 – Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-19626</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-19626</guid>
    <pubDate>Fri, 26 Mar 2021 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-19626</strong></p>
  <p>Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-19626">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-13870 – An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-13870</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-13870</guid>
    <pubDate>Fri, 05 Jun 2020 19:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-13870</strong></p>
  <p>An issue was discovered in the Comments plugin before 1.5.5 for Craft CMS. There is stored XSS via an asset volume name.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-13870">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
