Craft CMS
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 32 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from May 26, 2023 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Authenticated RCE via `condition.config` JSON cleanse bypass
Craft CMS 5.0.0-RC1 before 5.10.8 Stored XSS via Draft Name
Craft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password Reset
Craft CMS before 5.10.6 Authorization Bypass via structures/move-element
Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutation
Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContained
Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leak
Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escape
Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey
Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config
Monitor Craft CMS in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.