Craftcms
Craftcms Craft CMS: vulnerabilidades y CVE
Craftcms Craft CMS tiene 160 vulnerabilidades publicadas, 103 de ellas en los últimos 12 meses. 13 son críticas y 4 figuran en el catálogo de explotación activa de CISA.
CVE160
Últimos 12 meses103
Críticas13
Explotadas activamente4
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-32432 | Crítica (10) | 100% | ⚠ Explotación activa | 25 abr 2025 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft… |
| CVE-2025-35939 | Media (6.9) | 1.3% | ⚠ Explotación activa | 7 may 2025 | Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Craft CMS redirects requests that require… |
| CVE-2024-56145 | Crítica (9.3) | 97% | ⚠ Explotación activa | 18 dic 2024 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv`… |
| CVE-2025-23209 | Alta (8.1) | 22% | ⚠ Explotación activa | 18 ene 2025 | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-73858 | Media (5.3) | 0.43% | — | 23 sept 2026 | Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted values from public Freeform forms can be evaluated by the isolated Twig renderer when rendered… |
| CVE-2026-92593 | Alta (8.7) | 0.55% | — | 16 sept 2026 | Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a… |
| CVE-2026-92592 | Alta (8.7) | 0.65% | — | 16 sept 2026 | Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC… |
| CVE-2026-92591 | Alta (8.2) | 0.41% | — | 16 sept 2026 | Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed… |
| CVE-2026-92590 | Media (5.1) | 0.24% | — | 16 sept 2026 | Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can… |
| CVE-2026-92589 | Media (5.3) | 0.26% | — | 16 sept 2026 | Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but… |
| CVE-2026-79987 | Alta (8.7) | 0.65% | — | 10 sept 2026 | A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker. |
| CVE-2026-86732 | Alta (8.7) | 0.85% | — | 8 sept 2026 | Craft CMS versions before 5.10.12 contain a remote code execution vulnerability in the element-index endpoint that allows authenticated content editors to instantiate arbitrary classes through the criteria parameter.… |
| CVE-2026-86731 | Alta (7.1) | 0.31% | — | 8 sept 2026 | Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action). While the action requires the administrateUsers permission, it does… |
| CVE-2026-86730 | Alta (8.7) | 0.71% | — | 8 sept 2026 | Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post… |
| CVE-2026-79991 | Alta (7.1) | 0.51% | — | 2 sept 2026 | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering… |
| CVE-2026-79990 | Alta (8.7) | 0.45% | — | 2 sept 2026 | Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering… |
| CVE-2026-84802 | Media (5.3) | 0.28% | — | 2 sept 2026 | Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. Authenticated control panel users can submit… |
| CVE-2026-84801 | Alta (8.7) | 0.44% | — | 2 sept 2026 | Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateUsers permission to mint password reset URLs for administrator… |
| CVE-2026-84800 | Alta (7.1) | 0.35% | — | 2 sept 2026 | Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 contain a missing authorization vulnerability in AssetsController::actionReplaceFile. When a request supplies sourceAssetId and targetFilename but omits assetId, the target… |
| CVE-2026-84799 | Media (5.3) | 0.28% | — | 2 sept 2026 | Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fields. Attackers with a scoped GraphQL token can… |
| CVE-2026-84798 | Alta (7.1) | 0.35% | — | 2 sept 2026 | Craft CMS versions >= 5.0.0-RC1 and < 5.10.11 fail to perform an independent authorization check in ElementsController::actionDeleteForSite(). The method loads an element with checkForProvisionalDraft enabled and runs… |
| CVE-2026-84797 | Media (5.3) | 0.29% | — | 2 sept 2026 | Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate() that allows authenticated users with createEntries permission to delete peer provisional drafts.… |
| CVE-2026-84796 | Alta (8.7) | 0.47% | — | 2 sept 2026 | Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through ArgumentManager::prepareArguments(). Attackers with tokens scoped to… |
| CVE-2026-84795 | Crítica (9.2) | 0.51% | — | 2 sept 2026 | Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit… |
| CVE-2026-84794 | Alta (7.1) | 0.35% | — | 2 sept 2026 | Craft CMS versions before 5.10.11 lack authorization checks in the assets/move-asset endpoint when force=1 is supplied. Authenticated users without peer asset permissions can move their own assets into other users'… |
| CVE-2026-84793 | Media (4.8) | 0.25% | — | 2 sept 2026 | Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name field that fails to sanitize input. Administrators can inject arbitrary JavaScript payloads in the… |
| CVE-2026-84792 | Media (5.3) | 0.29% | — | 2 sept 2026 | Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entries into sections they cannot edit. Attackers… |
| CVE-2026-79988 | Alta (8.7) | 0.45% | — | 27 ago 2026 | The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities. |
| CVE-2026-78416 | Alta (8.7) | 1.0% | — | 24 ago 2026 | Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in… |
| CVE-2026-52889 | Crítica (9.8) | 1.3% | — | 19 ago 2026 | Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Referer URL, Current URL, Current URL without Query String, Query… |
| CVE-2026-72787 | Media (5.1) | 0.26% | — | 12 ago 2026 | Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can… |
| CVE-2026-72786 | Alta (7.1) | 0.46% | — | 12 ago 2026 | Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change passwords without verification. Attackers with edit users permission… |
| CVE-2026-72785 | Crítica (9.3) | 0.27% | — | 11 ago 2026 | Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can permanently modify… |
| CVE-2026-72784 | Media (6.9) | 0.24% | — | 11 ago 2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<Volume>Asset mutation, which fetches an attacker-supplied URL… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.