Vulnerabilities > Craftercms > Crafter CMS > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-05-16 CVE-2021-23265 Unspecified vulnerability in Craftercms Crafter CMS
A logged-in and authenticated user with a Reviewer Role may lock a content item.
network
low complexity
craftercms
4.0
2022-05-16 CVE-2021-23266 Improper Encoding or Escaping of Output vulnerability in Craftercms Crafter CMS
An anonymous user can craft a URL with text that ends up in the log viewer as is.
4.3
2021-12-02 CVE-2021-23258 Improper Control of Dynamically-Managed Code Resources vulnerability in Craftercms Crafter CMS
Authenticated users with Administrator or Developer roles may execute OS commands by SPEL Expression in Spring beans.
network
low complexity
craftercms CWE-913
6.5
2021-12-02 CVE-2021-23259 Improper Control of Dynamically-Managed Code Resources vulnerability in Craftercms Crafter CMS
Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage.
network
low complexity
craftercms CWE-913
6.5
2021-12-02 CVE-2021-23261 Unspecified vulnerability in Craftercms Crafter CMS
Authenticated administrators may override the system configuration file and cause a denial of service.
network
low complexity
craftercms
4.0
2021-12-02 CVE-2021-23262 Improper Control of Dynamically-Managed Code Resources vulnerability in Craftercms Crafter CMS
Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE.
network
low complexity
craftercms CWE-913
6.5
2021-12-02 CVE-2021-23263 Exposure of Resource to Wrong Sphere vulnerability in Craftercms Crafter CMS
Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary).
network
low complexity
craftercms CWE-668
5.0
2021-12-02 CVE-2021-23264 Exposure of Resource to Wrong Sphere vulnerability in Craftercms Crafter CMS
Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.
network
low complexity
craftercms CWE-668
6.4
2020-11-27 CVE-2017-15686 Cross-site Scripting vulnerability in Craftercms Crafter CMS 3.0.0
Crafter CMS Crafter Studio 3.0.1 is affected by: Cross Site Scripting (XSS), which allows remote attackers to steal users’ cookies.
network
craftercms CWE-79
4.3
2020-11-27 CVE-2017-15685 XML Injection (aka Blind XPath Injection) vulnerability in Craftercms Crafter CMS 3.0.0
Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE).
network
low complexity
craftercms CWE-91
5.0