« Back to list

Craft

Craft CMS: vulnerabilities and CVEs

Craft CMS has 4 published vulnerabilities, 4 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months4
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-92594High (8.7)0.43%—Sep 16, 2026
Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers()…
CVE-2026-50281High (7.1)0.43%—Jul 2, 2026
Craft CMS is a content management system (CMS). Versions 5.7.0 and above, prior to 5.9.21 contain a mass-assignment flaw in the bulk-duplicate element action. An attacker who is only able to duplicate their own entires…
CVE-2026-50284High (7.1)0.39%—Jul 1, 2026
Craft CMS is a content management system (CMS). In versions 5.0.0-RC1 through 5.9.21 and 4.0.0-RC1 through 4.17.14, theAssetsController::actionDeleteFolder() only requires the deleteAssets:<volume-uid> permission for…
CVE-2026-31266High (7.3)0.39%—May 27, 2026
Craft CMS 5.9.5 and earlier contains a Missing Authorization vulnerability in the migrate endpoint (/actions/app/migrate).

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System1
  2. T1190 Exploit Public-Facing Application1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Craft