Looking for the vulnerability index of Invicti's legacy products?

Craft CMS

Craft is a flexible user-friendly CMS for creating custom digital experiences on the web and beyond.

Severity Summary:

Critical: 9 High: 27 Medium: 47
Reference
Title
Severity
Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability
Critical
Craft CMS Improper Control of Generation of Code (Code Injection) Vulnerability
Critical
Craft CMS Improper Control of Generation of Code (Code Injection) Vulnerability
Critical
Craft CMS Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Critical
Craft CMS Improper Control of Generation of Code (Code Injection) Vulnerability
Critical
Craft CMS Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Critical
Craft CMS Allocation of Resources Without Limits or Throttling Vulnerability
Critical
Craft CMS Vulnerability
Critical
Craft CMS Improper Control of Generation of Code (Code Injection) Vulnerability
Critical
Craft CMS Use of Externally-Controlled Input to Select Classes or Code (Unsafe Reflection) Vulnerability
High
Craft CMS Improper Control of Generation of Code (Code Injection) Vulnerability
High
Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability
High
Craft CMS Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
High
Craft CMS Use of Externally-Controlled Input to Select Classes or Code (Unsafe Reflection) Vulnerability
High
Craft CMS Improper Control of Generation of Code (Code Injection) Vulnerability
High
Craft CMS Vulnerability
High
Craft CMS Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
High
Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability
High
Craft CMS Improper Control of Generation of Code (Code Injection) Vulnerability
High
Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability
High
Craft CMS Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
High
Craft CMS Improper Authentication Vulnerability
High
Craft CMS Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
High
Craft CMS Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
High
Craft CMS Authorization Bypass Through User-Controlled Key Vulnerability
High
Craft CMS Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Craft CMS Missing Encryption of Sensitive Data Vulnerability
High
Craft CMS Improper Neutralization of Formula Elements in a CSV File Vulnerability
High
Craft CMS Missing Encryption of Sensitive Data Vulnerability
High
Craft CMS Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
High