CVE Tools

Craftcms/cms

106 CVEs tracked. 4 of them are in CISA KEV.

This hub aggregates every CVE we track for Craftcms/cms, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Craftcms/cms CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Craftcms/cms CVEs per month
MonthCVEs
2024-100
2024-113
2024-121
2025-011
2025-020
2025-030
2025-041
2025-052
2025-060
2025-070
2025-082
2025-090
2025-100
2025-110
2025-120
2026-015
2026-0212
2026-0319
2026-043
2026-050
2026-060
2026-073
2026-0810
2026-090

Severity

How the 106 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1012%
  • High2934%
  • Medium4553%
  • Low11%

Latest CVEs

The 15 most recently published vulnerabilities affecting Craftcms/cms.

  1. GHSA-wg23-69c2-gjc8Craft CMS: Passkey login accepts replayed WebAuthn assertions—
  2. GHSA-957r-qf9p-67xwCraft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts—
  3. GHSA-596p-6jv8-775vCraft CMS: Authenticated leak of secret environment variables—
  4. GHSA-xxpx-f366-4xpqCraft CMS: Authorization bypass: view-only Categories user can modify category structure via structures/move-element—
  5. GHSA-rvmm-v933-jgxqCraft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics—
  6. GHSA-7hxc-f267-h5q7Craft CMS: Incorrect path validation could potentially lead to path traversal—
  7. GHSA-2rp4-x2j7-qmccCraft CMS: Stored XSS in the control panel via unescaped draft name—
  8. GHSA-p8x7-9vfw-p7vcCraft CMS: Arbitrary user password reset leading to administrator account takeover—
  9. GHSA-f5wm-88jv-g5hxCraft CMS: Authenticated RCE through Twig sandbox escape—
  10. GHSA-265m-7826-wjqmCraft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass—
  11. GHSA-86vw-x4ww-x467Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview—
  12. GHSA-c43v-4cr8-6mvpCraft CMS has authenticated path traversal in `assets/icon`, allowing local `.svg` file read—
  13. GHSA-x76w-8c62-48mgCraft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission—
  14. GHSA-95wr-3f2v-v2whCraft CMS has a host header injection leading to SSRF via resource-js endpoint—
  15. GHSA-3m9m-24vh-39wxServer-Side Request Forgery (SSRF) in Craft CMS with Asset Uploads Mutations—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store