brandonkelly
68 exploits
Active since May 2021
Craft CMS 4.0.0 to before 4.17.12 and 5.0.0 to before 5.9.18 - GraphQL Address PII Disclosure
Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior
Craft CMS < 5.9.18 AssetsController - Missing Volume Permission Check
Craft CMS < 3.6.7 - Remote Code Execution via Administrative Session Hijack
CVSS 9.8
Craft CMS unauthenticated Remote Code Execution (RCE)
CVSS 10.0
Craft CMS unauthenticated Remote Code Execution (RCE)
CVSS 10.0
Craft CMS unauthenticated Remote Code Execution (RCE)
CVSS 10.0
Craft CMS unauthenticated Remote Code Execution (RCE)
CVSS 10.0
Craft CMS Twig Template Injection RCE via FTP Templates Path
CVSS 9.8
CraftCMS - Remote Code Execution
CVSS 10.0
Craft CMS <4.17.0-beta.1/5.9.0-beta.1 - Privilege Escalation
CVSS 6.5
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
CVSS 7.2
Craft CMS 5.6.0-5.9.14 save-permissions - Missing Authorization
Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutations
Craft CMS resource-js Endpoint - Server-Side Request Forgery
Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior
CVSS 7.2
Craft CMS < 4.17.8 and 5.9.14 - Private Asset IDOR
CVSS 6.5
Craft CMS 4.x and 5.x - Unauthenticated Config Sync Operations
CVSS 6.5
Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform URL
CVSS 5.3
Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users
CVSS 4.3
Craft CMS 5.3.0-5.9.13 - Entry Section Move Authorization Bypass
CVSS 6.5
Craft CMS Vulnerable to Stored XSS in Revision Context Menu
CVSS 5.4
Amazon S3 for Craft CMS 2.0.2-2.2.4 - Bucket Listing Information Disclosure
Craft CMS Google Cloud Storage <2.2.1 - Bucket List Disclosure
Azure Blob Storage for Craft CMS Potential Sensitive Information Disclosure vulnerability