Vulnerabilities > Craftcms > Craft CMS > High

DATE CVE VULNERABILITY TITLE RISK
2024-07-25 CVE-2024-41800 Improper Authentication vulnerability in Craftcms Craft CMS
Craft is a content management system (CMS).
network
high complexity
craftcms CWE-287
7.5
2024-01-30 CVE-2023-36260 Injection vulnerability in Craftcms Craft CMS
An issue was discovered in the Feed Me plugin 4.6.1 for Craft CMS.
network
low complexity
craftcms CWE-74
7.5
2024-01-03 CVE-2024-21622 Unspecified vulnerability in Craftcms Craft CMS
Craft is a content management system.
network
low complexity
craftcms
8.8
2023-08-23 CVE-2023-40035 Injection vulnerability in Craftcms Craft CMS
Craft is a CMS for creating custom digital experiences on the web and beyond.
network
low complexity
craftcms CWE-74
7.2
2023-06-13 CVE-2023-30179 Code Injection vulnerability in Craftcms Craft CMS 3.7.59
CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI).
network
low complexity
craftcms CWE-94
7.2
2023-05-19 CVE-2023-32679 Injection vulnerability in Craftcms Craft CMS
Craft CMS is an open source content management system.
network
low complexity
craftcms CWE-74
7.2
2023-05-12 CVE-2023-30130 Code Injection vulnerability in Craftcms Craft CMS 3.8.1
An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.
network
low complexity
craftcms CWE-94
8.8
2022-12-05 CVE-2022-37783 Insufficiently Protected Credentials vulnerability in Craftcms Craft CMS
All Craft CMS versions between 3.0.0 and 3.7.32 disclose password hashes of users who authenticate using their E-Mail address or username in Anti-CSRF-Tokens.
network
low complexity
craftcms CWE-522
7.5
2021-06-30 CVE-2021-27903 Missing Authorization vulnerability in Craftcms Craft CMS
An issue was discovered in Craft CMS before 3.6.7.
network
low complexity
craftcms CWE-862
7.5
2020-03-04 CVE-2020-9757 Injection vulnerability in Craftcms Craft CMS
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.
network
low complexity
craftcms CWE-74
7.5