Vulnerabilities > Craftcms > Craft CMS > Critical
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-06-25 | CVE-2024-37843 | SQL Injection vulnerability in Craftcms Craft CMS Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint. | 9.8 |
2023-09-13 | CVE-2023-41892 | Unspecified vulnerability in Craftcms Craft CMS Craft CMS is a platform for creating digital experiences. | 9.8 |
2021-06-30 | CVE-2021-27903 | Missing Authorization vulnerability in Craftcms Craft CMS An issue was discovered in Craft CMS before 3.6.7. | 9.8 |
2020-03-04 | CVE-2020-9757 | Injection vulnerability in Craftcms Craft CMS The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller. | 9.8 |
2019-10-24 | CVE-2019-15929 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Craftcms Craft CMS In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them. | 9.8 |