craftcms
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 115 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from April 22, 2017 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Craft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section permissions
Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users
Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform URL
Craft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted users
Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)
Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior
Craft CMS Vulnerable to Stored XSS in Revision Context Menu
Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
Craft CMS vulnerable to behavior injection RCE via EntryTypesController
Monitor craftcms in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.