Looking for the vulnerability index of Invicti's legacy products?

Craft CMS

Craft is a flexible user-friendly CMS for creating custom digital experiences on the web and beyond.

Severity Summary:

Critical: 5 High: 16 Medium: 31
Reference
Title
Severity
Craft CMS Vulnerability
Critical
Craft CMS Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Critical
Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability
Critical
Craft CMS Improper Control of Generation of Code (Code Injection) Vulnerability
Critical
Craft CMS Improper Control of Generation of Code (Code Injection) Vulnerability
Critical
Craft CMS Improper Authentication Vulnerability
High
Craft CMS Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
High
Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability
High
Craft CMS Improper Neutralization of Formula Elements in a CSV File Vulnerability
High
Craft CMS Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
High
Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability
High
Craft CMS Improper Control of Generation of Code (Code Injection) Vulnerability
High
Craft CMS Improper Control of Generation of Code (Code Injection) Vulnerability
High
Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability
High
Craft CMS Improper Control of Generation of Code (Code Injection) Vulnerability
High
Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability
High
Craft CMS Vulnerability
High
Craft CMS Missing Encryption of Sensitive Data Vulnerability
High
Craft CMS Missing Encryption of Sensitive Data Vulnerability
High
Craft CMS Unrestricted Upload of File with Dangerous Type Vulnerability
High
Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability
High
Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Craft CMS Vulnerability
Medium
Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability
Medium
Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium