Where
-Infinity
0

Vendor Risk Score

See how craftcms compares to other vendors in security performance

View Risk Score →

composer/craftcms/cmsCraft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section permissions

Risk 38
Severity
4.9
First published (updated )

CraftCMS Craft CMSCraft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users

Risk 22
Severity
1.3
First published (updated )

CraftCMS Craft CMSCraft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform URL

Risk 27
Severity
2.7
First published (updated )

CraftCMS Craft CMSCraft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted users

Risk 41
Severity
6.9
First published (updated )

CraftCMS Craft CMSCraft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)

Risk 38
Severity
4.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/craftcms/cmsCraft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior

Risk 72
Severity
8.6
First published (updated )

composer/craftcms/cmsCraft CMS Vulnerable to Stored XSS in Revision Context Menu

Risk 25
Severity
5.3
EPSS
0.03%
First published (updated )

CraftCMS Craft CMSCraft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()

Risk 61
Severity
7.7
EPSS
0.03%
First published (updated )

CraftCMS Craft CMSCraft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController

Risk 53
Severity
8.6
EPSS
0.02%
First published (updated )

composer/craftcms/cmsCraft CMS vulnerable to behavior injection RCE via EntryTypesController

Risk 53
Severity
8.6
EPSS
0.02%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CraftCMS Craft CMSCraft CMS has a Path Traversal Vulnerability in AssetsController

Risk 19
Severity
5.3
EPSS
0.03%
First published (updated )

CraftCMS Craft CMSCraftCMS has an RCE vulnerability via relational conditionals in the control panel

Risk 56
Severity
8.8
EPSS
0.10%
First published (updated )

CraftCMS Craft CMSCraftCMS's `ElementSearchController` Affected by Blind SQL Injection

Risk 56
Severity
8.8
EPSS
0.03%
First published (updated )

composer/craftcms/cmsCraft has Reflective XSS via incomplete return URL sanitization

Risk 30
Severity
6.9
EPSS
0.03%
First published (updated )

composer/craftcms/commerceCraft Commerce has a Potential IDOR in Commerce carts

Risk 27
Severity
6.3
EPSS
0.05%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/craftcms/commerceCraft Commerce has Stored XSS in Craft Commerce Order Details Slideout

Risk 25
Severity
5.4
EPSS
0.01%
First published (updated )

composer/craftcms/commerceCraft Commerce has Stored XSS in Inventory Location Name

Risk 23
Severity
4.8
EPSS
0.01%
First published (updated )

composer/craftcms/commerceMultiple Stored XSS in Commerce Inventory Page Leading to Session Hijacking

Risk 49
Severity
8.6
EPSS
0.03%
First published (updated )

composer/craftcms/commerceCraft Commerce has a SQL Injection in Commerce Inventory Table Sorting

Risk 56
Severity
8.8
EPSS
0.01%
First published (updated )

composer/craftcms/commerceCraft Commerce has Stored XSS while updating Order Status from Orders Table

Risk 16
Severity
4.8
EPSS
0.01%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/craftcms/commerceCraft Commerce has a SQL Injection in Commerce Purchasables Table Sorting

Risk 56
Severity
8.8
EPSS
0.03%
First published (updated )

composer/craftcms/cmsCraft has a potential information disclosure vulnerability in preview tokens

Risk 16
Severity
4.3
EPSS
0.01%
First published (updated )

CraftCMS Craft CMSCraft has an unauthenticated activation email trigger with potential user enumeration

Risk 23
Severity
6.9
EPSS
0.05%
First published (updated )

CraftCMS Craft CMSCraft is affected by potential authenticated Remote Code Execution via Twig SSTI

Risk 53
Severity
8.6
EPSS
0.05%
First published (updated )

CraftCMS Craft CMSCraft has a Permission Bypass and IDOR in Duplicate Entry Action

Risk 19
Severity
5.3
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

CraftCMS Craft CMSCraft has a Twig Function Blocklist Bypass

Risk 55
Severity
9.4
EPSS
0.09%
First published (updated )

CraftCMS Craft CMSCraft Affected by Entries Authorship Spoofing via Mass Assignment

Risk 29
Severity
7.1
EPSS
0.04%
First published (updated )

CraftCMS Craft CMSCraft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates

Risk 55
Severity
9.4
EPSS
0.50%
First published (updated )

CraftCMS Craft CMSCraft affected by IDOR via GraphQL @parseRefs

Risk 33
Severity
8.7
EPSS
0.04%
First published (updated )

CraftCMS Craft CMSCraft affected by authenticated RCE via Twig SSTI - create() function + Symfony Process gadget

Risk 49
Severity
7.5
EPSS
0.06%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203