brandonkelly
56 exploits
Active since May 2021
Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action
Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutations
Craft CMS has a host header injection leading to SSRF via resource-js endpoint
Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior
CVSS 7.2
Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)
CVSS 6.5
Craft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted users
CVSS 6.5
Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform URL
CVSS 5.3
Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users
CVSS 4.3
Craft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section permissions
CVSS 6.5
Craft CMS Vulnerable to Stored XSS in Revision Context Menu
CVSS 5.4
Amazon S3 for Craft CMS 2.0.2-2.2.4 - Bucket Listing Information Disclosure
Google Cloud Storage for Craft CMS has an Information Disclosure Vulnerability
Azure Blob Storage for Craft CMS Potential Sensitive Information Disclosure vulnerability
RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugin
Craft CMS has a Path Traversal Vulnerability in AssetsController
CVSS 4.3
Craft CMS vulnerable to behavior injection RCE via EntryTypesController
CVSS 7.2
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
CVSS 7.2
Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()
CVSS 9.8
Craft CMS <5.9.9/4.17.4 - RCE
CVSS 8.8
Craft CMS - SQL Injection
CVSS 8.8
Craft CMS <4.17.4/5.9.7 - CSRF
CVSS 4.3
Craft CMS 5.8.21 - Authenticated RCE
CVSS 7.2
Craft CMS <4.17.0-beta.1/5.9.0-beta.1 - Info Disclosure
CVSS 7.5
Craft CMS <4.17.0-beta.1/5.9.0-beta.1 - RCE
CVSS 9.1
Craft CMS <4.17.0-beta.1/5.9.0-beta.1 - Privilege Escalation
CVSS 6.5