Vulnerabilities > Craftcms > Craft CMS > 3.1.31
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-05-09 | CVE-2022-29933 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Craftcms Craft CMS Craft CMS through 3.7.36 allows a remote unauthenticated attacker, who knows at least one valid username, to reset the account's password and take over the account by providing a crafted HTTP header to the application while using the password reset functionality. | 6.8 |
2022-04-03 | CVE-2022-28378 | Cross-site Scripting vulnerability in Craftcms Craft CMS Craft CMS before 3.7.29 allows XSS. | 4.3 |
2021-06-30 | CVE-2021-27902 | Cross-site Scripting vulnerability in Craftcms Craft CMS An issue was discovered in Craft CMS before 3.6.0. | 4.3 |
2021-06-30 | CVE-2021-27903 | Missing Authorization vulnerability in Craftcms Craft CMS An issue was discovered in Craft CMS before 3.6.7. | 7.5 |
2021-05-07 | CVE-2021-32470 | Cross-site Scripting vulnerability in Craftcms Craft CMS Craft CMS before 3.6.13 has an XSS vulnerability. | 4.3 |
2021-03-26 | CVE-2020-19626 | Cross-site Scripting vulnerability in Craftcms Craft CMS 3.1.31 Cross Site Scripting (XSS) vulnerability in craftcms 3.1.31, allows remote attackers to inject arbitrary web script or HTML, via /admin/settings/sites/new. | 3.5 |
2020-03-04 | CVE-2020-9757 | Injection vulnerability in Craftcms Craft CMS The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller. | 7.5 |