Skip to content
RequestGuard Vulnerabilities
Pricing

craftcms/cms

Craft CMS

Composer latest 5.11.3 proprietary

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

5.11.3

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Critical

127 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

127
GHSA-f3gw-9ww9-jmc3 critical CISA KEV

Craft CMS Allows Remote Code Execution

Affected range

ECOSYSTEM: introduced 3.0.0-RC1; fixed 3.9.15ECOSYSTEM: introduced 4.0.0-RC1; fixed 4.14.15ECOSYSTEM: introduced 5.0.0-RC1; fixed 5.6.17>=5.0.0-RC1,<=5.6.16|>=4.0.0-RC1,<=4.14.14|>=3.0.0-RC1,<=3.9.14

Fixed versions: 3.9.15, 4.14.15, 5.6.17

GHSA-2p6p-9rc9-62j9 critical CISA KEV

Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled

Affected range

ECOSYSTEM: introduced 5.0.0-RC1; fixed 5.5.2ECOSYSTEM: introduced 4.0.0-RC1; fixed 4.13.2ECOSYSTEM: introduced 3.0.0; fixed 3.9.14>=3.0.0,<3.9.14|>=4.0.0-RC1,<4.13.2|>=5.0.0-RC1,<5.5.2

Fixed versions: 5.5.2, 4.13.2, 3.9.14

GHSA-x684-96hh-833x high CISA KEV

Craft CMS has a potential RCE with a compromised security key

Affected range

ECOSYSTEM: introduced 5.0.0-RC1; fixed 5.5.8ECOSYSTEM: introduced 4.0.0-RC1; fixed 4.13.8>=4.0.0-RC1,<4.13.8|>=5.0.0-RC1,<5.5.5

Fixed versions: 5.5.8, 4.13.8

GHSA-7vrx-9684-xrf2 moderate CISA KEV

Craft CMS stores arbitrary content provided by unauthenticated users in session files

Affected range

ECOSYSTEM: introduced 5.0.0-alpha.1; fixed 5.7.5ECOSYSTEM: introduced 0; fixed 4.15.3<4.15.3|>=5.0.0-alpha.1,<5.7.5

Fixed versions: 5.7.5, 4.15.3

Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs

Affected range

ECOSYSTEM: introduced 5.0.0-RC1; fixed 5.10ECOSYSTEM: introduced 4.0.0-RC1; fixed 4.18>=4.0.0-RC1,<4.18|>=5.0.0-RC1,<5.10

Fixed versions: 5.10, 4.18

Craft CMS Vulnerable to Authenticated RCE via "craft.app.fs.write()" in Twig Templates

Affected range

ECOSYSTEM: introduced 5.0.0-RC1; fixed 5.9.0-beta.1ECOSYSTEM: introduced 4.0.0-RC1; fixed 4.17.0-beta.1>=4.0.0-RC1,<4.17.0-beta.1|>=5.0.0-RC1,<5.9.0-beta.1

Fixed versions: 5.9.0-beta.1, 4.17.0-beta.1

Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements

Affected range

ECOSYSTEM: introduced 5.7.0; fixed 5.9.21>=5.7.0,<5.9.21

Fixed versions: 5.9.21

Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves

Affected range

ECOSYSTEM: introduced 5.0.0-RC1; fixed 5.9.21ECOSYSTEM: introduced 4.0.0-RC1; fixed 4.17.14>=4.0.0-RC1,<4.17.14|>=5.0.0-RC1,<5.9.21

Fixed versions: 5.9.21, 4.17.14

Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget

Affected range

ECOSYSTEM: introduced 5.0.0-RC1; fixed 5.9.23ECOSYSTEM: introduced 4.0.0-RC1; fixed 4.17.16>=4.0.0-RC1,<4.17.15|>=5.0.0-RC1,<5.9.22

Fixed versions: 5.9.23, 4.17.16

Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap

Affected range

ECOSYSTEM: introduced 5.0.0-RC1; fixed 5.9.21>=5.0.0-RC1,<5.9.21

Fixed versions: 5.9.21

Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets

Affected range

ECOSYSTEM: introduced 5.0.0-RC1; fixed 5.9.22ECOSYSTEM: introduced 4.0.0-RC1; fixed 4.17.15>=4.0.0-RC1,<4.17.15|>=5.0.0-RC1,<5.9.22

Fixed versions: 5.9.22, 4.17.15

Craft CMS Arbitrary System File Read

Affected range

ECOSYSTEM: introduced 5.0.0-alpha.1; fixed 5.4.9ECOSYSTEM: introduced 3.5.13; fixed 4.12.8>=3.5.13,<=4.12.6.1|>=5.0.0-alpha.1,<=5.4.7.1

Fixed versions: 5.4.9, 4.12.8

Craft CMS vulnerable to Remote Code Execution via validatePath bypass

Affected range

ECOSYSTEM: introduced 4.0.0-RC1; fixed 4.4.15ECOSYSTEM: introduced 3.0.0; fixed 3.8.15>=3.0.0,<=3.8.14|>=4.0.0-RC1,<=4.4.14

Fixed versions: 4.4.15, 3.8.15

Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass

Affected range

ECOSYSTEM: introduced 5.0.0-RC1; fixed 5.10.6ECOSYSTEM: introduced 4.0.0-RC1; fixed 4.18.2>=4.0.0-RC1,<4.18.2|>=5.0.0-RC1,<5.10.6

Fixed versions: 5.10.6, 4.18.2

Craft CMS: Authenticated RCE through Twig sandbox escape

Affected range

ECOSYSTEM: introduced 5.0.0-RC1; fixed 5.10.7ECOSYSTEM: introduced 4.0.0-RC1; fixed 4.18.3>=4.0.0-RC1,<4.18.3|>=5.0.0-RC1,<5.10.7

Fixed versions: 5.10.7, 4.18.3

Show 75 more advisories
GHSA-2453-mppf-46cj Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`
GHSA-h7vq-5qgw-jwwq CSV Injection Vulnerability
GHSA-33m5-hqp9-97pw Craft CMS's Missing Volume Permission Check in AssetsController::actionShowInFolder Allows Information Disclosure
GHSA-qrgm-p9w5-rrfw Craft CMS has Potential Authenticated Remote Code Execution via Malicious Attached Behavior
GHSA-gj2p-p9m4-c8gw Craft CMS's Missing Authorization in GraphQL Address Resolver Allows Cross-Scope PII Disclosure
GHSA-qx2q-q59v-wf3j Craft CMS vulnerable to behavior injection RCE via EntryTypesController
GHSA-7jx7-3846-m7w7 Craft CMS Vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
GHSA-4484-8v2f-5748 Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
GHSA-2fph-6v5w-89hh Craft CMS is Vulnerable to Authenticated Remote Code Execution via Malicious Attached Behavior
GHSA-cc7p-2j3x-x7xf Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()
GHSA-fp5j-j7j4-mcxc CraftCMS has an RCE vulnerability via relational conditionals in the control panel
GHSA-g7j6-fmwx-7vp8 CraftCMS's `ElementSearchController` Affected by Blind SQL Injection
GHSA-234q-vvw3-mrfq Craft CMS has unauthenticated activation email trigger with potential user enumeration
GHSA-7x43-mpfg-r9wj Craft CMS has IDOR via GraphQL @parseRefs
GHSA-gp2f-7wcm-5fhx Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding
GHSA-fxp3-g6gw-4r4v Craft CMS: GraphQL Asset Mutation Privilege Escalation
GHSA-f3cw-hg6r-chfv Craft CMS vulnerable to Potential Remote Code Execution via missing path normalization & Twig SSTI
GHSA-7c58-g782-9j38 Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI
GHSA-v64r-7wg9-23pr Unauthenticated Craft CMS users can trigger a database backup
GHSA-255j-qw47-wjh5 Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
GHSA-fjx5-xm7q-whvj CraftCMS allows remote attacker to execute arbitrary code via crafted script to Section parameter
GHSA-jrh5-vhr9-qh7q Local File System Validation Bypass Leading to File Overwrite, Sensitive File Access, and Potential Code Execution
GHSA-h972-v458-m892 Craft CMS discloses password hashes
GHSA-r342-vjc4-wrmj Craft CMS PHP Code Injection Vulnerability
GHSA-j7fx-v37j-v3w7 Craft CMS Vulnerable to Server-Side Template Injection
GHSA-5cjr-78cq-3wrg Improper account password reset in Craft CMS
GHSA-xrqc-p465-2xvg Craft CMS: Stored XSS via Structure entry title in table view
GHSA-43cq-c2gq-pfpw Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check
GHSA-qh45-9g5p-m2v4 Craft CMS: Unauthorized Deletion of Source Assets During File Replacement
GHSA-287w-mxq6-x2cp Craft CMS: Sensitive File Disclosure / Server-Side File Read
GHSA-wmx7-pw49-88jx Craft CMS Allows TOTP Token To Stay Valid After Use
GHSA-m3v5-gjj9-rg24 Craft CMS vulnerable to HTML injection
GHSA-qpgm-gjgf-8c2x Craft CMS XSS in RSS widget feed
GHSA-j5g9-j7r4-6qvx Craft CMS Privilege Escalation
GHSA-6qjx-787v-6pxr Craft CMS stored XSS in indexedVolumes
GHSA-qcrj-6ffc-v7hq Craft CMS Stored Cross-site Scripting Injection Vulnerability
GHSA-xxpx-f366-4xpq Craft CMS: Authorization bypass: view-only Categories user can modify category structure via structures/move-element
GHSA-957r-qf9p-67xw Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
GHSA-596p-6jv8-775v Craft CMS: Authenticated leak of secret environment variables
GHSA-rvmm-v933-jgxq Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
GHSA-2rp4-x2j7-qmcc Craft CMS: Stored XSS in the control panel via unescaped draft name
GHSA-x76w-8c62-48mg Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
GHSA-9p7c-v5x3-rfx8 Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
GHSA-95wr-3f2v-v2wh Craft CMS has a host header injection leading to SSRF via resource-js endpoint
GHSA-jq2f-59pj-p3m3 Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action
GHSA-3m9m-24vh-39wx Server-Side Request Forgery (SSRF) in Craft CMS with Asset Uploads Mutations
GHSA-f582-6gf6-gx4g Craft CMS has an authorization bypass which allows any control panel user to move entries without permissions
GHSA-3pvf-vxrv-hh9c Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)
GHSA-6mrr-q3pj-h53w Craft CMS: Unauthenticated Users Can Perform Restricted Project Config Sync Operations
GHSA-3x4w-mxpf-fhqq Craft CMS Vulnerable to Stored XSS in Revision Context Menu
GHSA-472v-j2g4-g9h2 Craft CMS has a Path Traversal Vulnerability in AssetsController
GHSA-fvwq-45qv-xvhv CraftCMS vulnerable to reflective XSS via incomplete return URL sanitization
GHSA-5fvc-7894-ghp4 Craft CMS has Twig Function Blocklist Bypass
GHSA-2xfc-g69j-x2mp Craft CMS: Entries Authorship Spoofing via Mass Assignment
GHSA-jxm3-pmm2-9gf6 Craft CMS has Permission Bypass and IDOR in Duplicate Entry Action
GHSA-qc86-q28f-ggww Craft CMS has potential authenticated Remote Code Execution via Twig SSTI
GHSA-94rc-cqvm-m4pw Craft CMS Vulnerable to Authenticated RCE via Twig SSTI - create() function + Symfony Process gadget
GHSA-x27p-wfqw-hfcc Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation
GHSA-v2gc-rm6g-wrw9 Craft CMS: Cloud Metadata SSRF Protection Bypass via IPv6 Resolution
GHSA-6fx5-5cw5-4897 Craft CMS Race condition in Token Service potentially allows for token usage greater than the token limit
GHSA-3jh3-prx3-w6wc Craft CMS has Stored XSS in Table Field via "HTML" Column Type
GHSA-m5r2-8p9x-hp5m Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via Alternative IP Notation
GHSA-9f5h-mmq6-2x78 Craft CMS Vulnerable to Stored XSS in Number Prefix & Suffix Fields
GHSA-8jr8-7hr4-vhfx Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via HTTP Redirect
GHSA-53vf-c43h-j2x9 Craft CMS vulnerable to potential information disclosure via unchecked asset relocation
GHSA-742x-x762-7383 Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI
GHSA-crcq-738g-pqvc Craft CMS Potential Remote Code Execution via Twig SSTI
GHSA-2vcf-qxv3-2mgw Craft CMS has a theoretical bypass for CVE-2025-23209
GHSA-28h4-788g-rh42 Craft CMS vulnerable to stored XSS in breadcrumb list and title fields
GHSA-72pf-cvwq-vgqg Craft CMS Cross-site Scripting (XSS) Vulnerability
GHSA-j27g-r58q-624w Craft CMS subject to URL forgery
GHSA-mw37-wx8p-gp45 Craft CMS vulnerable to Cross-site Scripting via entry revisions and drafts
GHSA-f546-v666-559x Craft CMS Cross-site Scripting vulnerability
GHSA-3cvm-7wrh-qrf9 Craft CMS vulnerable to stored Cross-site Scripting via /admin/settings/fields page
GHSA-wxvf-839f-jqmh Craft CMS Cross site Scripting vulnerability