Vulnerabilities > Craftercms > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-12-02 CVE-2021-23264 Exposure of Resource to Wrong Sphere vulnerability in Craftercms Crafter CMS
Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.
network
low complexity
craftercms CWE-668
critical
9.1
2020-11-27 CVE-2017-15681 Path Traversal vulnerability in Craftercms Crafter CMS 3.0.0
In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to RCE.
network
low complexity
craftercms CWE-22
critical
9.8