← Back to News Iceland Security Dashboard Browse all tags
craft-cms

Craft Cms

craft-cms 8craft cms 4

CVEs tagged with this vendor (8)

CVE-2024-56145 🚨 Craft CMS
CVE-2024-56145 is a critical remote code execution vulnerability in Craft CMS affecting versions prior to 3.9.14, 4.13.2, and 5.5.2 when the php.ini directive r…
CVE-2025-23209 🚨 Craft CMS
CVE-2025-23209 is a remote code execution vulnerability in Craft CMS versions 4 and 5, classified under CWE-94, with a CVSS v3.1 score of 8.0 (HIGH). The vulner…
CVE-2025-32432 🚨 Craft CMS
Craft CMS versions 3.0.0-RC1 through 3.9.14, 4.0.0-RC1 through 4.14.14, and 5.0.0-RC1 through 5.6.16 are vulnerable to remote code execution due to improper con…
CVE-2025-35939 🚨 Craft CMS
CVE-2025-35939 affects Craft CMS versions prior to 5.7.5 and 4.15.3, allowing unauthenticated attackers to store arbitrary content, including PHP code, in serve…
CVE-2026-28697 CVSS 9.1 craft_cms
CVE-2026-28697 is a critical Remote Code Execution vulnerability in Craft CMS versions prior to 4.17.0-beta.1 and 5.9.0-beta.1. It allows authenticated administ…
CVE-2026-28783 CVSS 9.1 craft_cms
Craft CMS versions prior to 5.9.0-beta.1 and 4.17.0-beta.1 contain a critical vulnerability due to an incomplete blocklist of dangerous PHP functions in Twig no…
CVE-2026-28695 CVSS 7.2 craft_cms
Craft CMS versions 5.8.21 and earlier contain an authenticated admin Remote Code Execution vulnerability via Server-Side Template Injection. The flaw allows ins…
CVE-2026-28784 CVSS 7.2 craft_cms
CVE-2026-28784 is a high-severity remote code execution vulnerability in Craft CMS versions prior to 5.8.22 and 4.16.18. The flaw allows an attacker with admini…

Articles tagged with this vendor

No articles tagged with this vendor yet.