brandonkelly
68 exploits
Active since May 2021
RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugin
Craft CMS < 4.17.5 and 5.9.11 - AssetsController Path Traversal File Deletion
CVSS 4.3
Craft CMS vulnerable to behavior injection RCE via EntryTypesController
CVSS 7.2
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
CVSS 7.2
Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()
CVSS 9.8
Craft CMS 5.x < 5.9.9 and 4.x < 4.17.4 - Authenticated Remote Code Execution
CVSS 8.8
Craft CMS 5.0.1-5.9.8 - Authenticated SQL Injection via ElementSearchController
CVSS 8.8
Craft CMS 4.0.0-4.17.3 - Cross-Site Request Forgery via Preview Token Endpoint
CVSS 4.3
Craft CMS 5.8.21 - Authenticated RCE
CVSS 7.2
Craft CMS <4.17.0-beta.1/5.9.0-beta.1 - Info Disclosure
CVSS 7.5
Craft CMS <4.17.0-beta.1/5.9.0-beta.1 - RCE
CVSS 9.1
Craft CMS <4.17.0-beta.1/5.9.0-beta.1 - Privilege Escalation
CVSS 6.5
Craft CMS <5.9.0-beta.1/4.17.0-beta.1 - Privilege Escalation
CVSS 4.3
Craft CMS <5.9.0-beta.2/4.17.0-beta.2 - Auth Bypass
CVSS 5.3
Craft CMS 4.5.0-RC1-4.16.18/5.0.0-RC1-5.8.22 - XSS
CVSS 4.8
Craft CMS 4.5.0-RC1-4.16.18/5.0.0-RC1-5.8.22 - SSRF
CVSS 6.3
Craft CMS 4.5.0-RC1-4.16.18/5.0.0-RC1-5.8.22 - Auth Bypass
CVSS 4.8
Craft CMS GraphQL Asset IPv6 - Server-Side Request Forgery
CVSS 6.5
Craft CMS < 3.6.13 - Cross-Site Scripting
CVSS 6.1
Craft CMS 4.2.0.1 - Cross-Site Scripting in BaseElementSelectInput Label Renderer
CVSS 5.4
Craft CMS 4.2.0.1 - Stored Cross-Site Scripting via Admin Settings Fields Page
CVSS 5.4
Craft CMS 4.2.0.1 - Cross-Site Scripting in Cp.php Helper
CVSS 5.4
Craft CMS 4.2.0.1 - Stored Cross-Site Scripting in Admin MyAccount Page
CVSS 5.4
Craft CMS <= 4.4.11 - Authenticated Stored Cross-Site Scripting in Field Names
CVSS 5.4
Craft CMS 3.0.0-3.8.3 and 4.0.0-4.4.3 - Stored Cross-Site Scripting via Feed Widget Title
CVSS 6.1