Vulnerabilities > Craftcms > Craft CMS > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-06-25 CVE-2024-37843 SQL Injection vulnerability in Craftcms Craft CMS
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
network
low complexity
craftcms CWE-89
critical
9.8
2023-09-13 CVE-2023-41892 Code Injection vulnerability in Craftcms Craft CMS
Craft CMS is a platform for creating digital experiences.
network
low complexity
craftcms CWE-94
critical
9.8