Craft CMS
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 55 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from May 26, 2023 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL
Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution
Craft CMS before 4.18.6 Remote Code Execution via signed cookie
Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer
Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields
Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder
Low-privilege RCE through element-search eager loading
Craft CMS before 5.10.12 Remote Code Execution via element-index
Craft CMS 5.0.0-RC1 before 5.10.12 Permission Escalation via UsersController
Craft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCE
Monitor Craft CMS in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.