Where
-Infinity
0

Vendor Risk Score

See how pixel & tonic compares to other vendors in security performance

View Risk Score →

Pixel & Tonic Craft CMSCraft CMS - Authenticated Path Traversal in assets/icon Extension Parameter

Risk 40
Severity
7.1
First published (updated )

Pixel & Tonic Craft CMSCraft CMS - Authorization Bypass in assets/preview-file Endpoint

Risk 26
Severity
5.3
First published (updated )

Pixel & Tonic Craft CMSCraft CMS - Multiple Stored Cross-Site Scripting in Settings Names and Field Options

Risk 29
Severity
4.6
First published (updated )

Pixel & Tonic Craft CMSCraft CMS - Missing Authorization in assets/preview-thumb Endpoint

Risk 26
Severity
5.3
First published (updated )

Pixel & Tonic Craft CMSCraft CMS - Stored XSS in Table Field via Row Heading Column Type

Risk 29
Severity
4.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Pixel & Tonic Craft CMSCraft CMS - Stored XSS via User Group Name in User Permissions Page

Risk 29
Severity
4.6
First published (updated )

Pixel & Tonic Craft CMSCraft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (…

Risk 51
Severity
7.3
First published (updated )

Pixel & Tonic Craft CMSCraft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutations

Risk 40
Severity
5.5
First published (updated )

Pixel & Tonic Craft CommerceCraft Commerce: Blind SQL Injection via hasVariant/hasProduct

Risk 79
Severity
8.7
First published (updated )

composer/craftcms/commerceCraft Commerce: SQL Injection can lead to Remote Code Execution via TotalRevenue Widget

Risk 72
Severity
7.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

composer/craftcms/commerceCraft Commerce: Unauthenticated information disclosure in `commerce/payments/pay` can leak some customer order data on anonymous payments

Risk 14
Severity
1.7
First published (updated )

Pixel & Tonic Craft CMS 5End of life details

EOL
Dec 31, 2031
Support Ends
Dec 31, 2030
First published (updated )

Pixel & Tonic Craft CMS 5End of life details

EOL
Dec 31, 2031
Support Ends
Dec 31, 2030
First published (updated )

Pixel & Tonic Craft CMS 4Reached end of life

EOL
Apr 30, 2026
Support Ends
Apr 30, 2025
First published (updated )

Pixel & Tonic Craft CMS 4Reached end of life

EOL
Apr 30, 2026
Support Ends
Apr 30, 2025
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Pixel & Tonic Craft CMS 3Reached end of life

EOL
Apr 30, 2024
Support Ends
Apr 30, 2023
First published (updated )

Pixel & Tonic Craft CMS 3Reached end of life

EOL
Apr 30, 2024
Support Ends
Apr 30, 2023
First published (updated )

Pixel & Tonic Craft CMS 2Reached end of life

EOL
Jan 31, 2022
Support Ends
Jan 31, 2020
First published (updated )

Pixel & Tonic Craft CMS 2Reached end of life

EOL
Jan 31, 2022
Support Ends
Jan 31, 2020
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203