Craft is a flexible user-friendly CMS for creating custom digital experiences on the web and beyond.
Craft CMS Missing Encryption of Sensitive Data Vulnerability
High
Craft CMS Use of Externally-Controlled Input to Select Classes or Code (Unsafe Reflection) Vulnerability
High
Craft CMS Unrestricted Upload of File with Dangerous Type Vulnerability
High
Craft CMS Improper Control of Generation of Code (Code Injection) Vulnerability
High
Craft CMS Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
High
Craft CMS Missing Encryption of Sensitive Data Vulnerability
High
Craft CMS Use of Externally-Controlled Input to Select Classes or Code (Unsafe Reflection) Vulnerability
High
Craft CMS Improper Neutralization of Formula Elements in a CSV File Vulnerability
High
Craft CMS Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection) Vulnerability
High
Craft CMS Weak Password Recovery Mechanism for Forgotten Password Vulnerability
High
Craft CMS Authorization Bypass Through User-Controlled Key Vulnerability
High
Craft CMS Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
High
Craft CMS Authorization Bypass Through User-Controlled Key Vulnerability
Medium
Craft CMS Authorization Bypass Through User-Controlled Key Vulnerability
Medium
Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Craft CMS Authorization Bypass Through User-Controlled Key Vulnerability
Medium
Craft CMS Missing Authentication for Critical Function Vulnerability
Medium
Craft CMS Authorization Bypass Through User-Controlled Key Vulnerability
Medium
Craft CMS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Medium
Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Craft CMS Server-Side Request Forgery (SSRF) Vulnerability
Medium
Craft CMS Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability
Medium
Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Craft CMS Server-Side Request Forgery (SSRF) Vulnerability
Medium
Craft CMS Server-Side Request Forgery (SSRF) Vulnerability
Medium
Craft CMS Server-Side Request Forgery (SSRF) Vulnerability
Medium
Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Craft CMS Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Medium
Craft CMS Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Medium
Craft CMS Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability
Medium