craft
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 15 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from January 18, 2025 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget
Craft has an unauthenticated activation email trigger with potential user enumeration
Cloud Metadata SSRF Protection Bypass via IPv6 Resolution
Craft has a SQL Injection in Element Indexes via criteria[orderBy]
Craft has a SSRF in GraphQL Asset Mutation via Alternative IP Notation
Craft has a SSRF in GraphQL Asset Mutation via HTTP Redirect
Craft has a save_images_Asset graphql mutation can be abused to exfiltrate AWS credentials of underlying host
Craft has a Stored XSS in Entry Types Name
Craft Potential Remote Code Execution via Twig SSTI
Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability
Monitor craft in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.