brandonkelly
83 exploits
Active since May 2021
Craft CMS <4.17.0-beta.1/5.9.0-beta.1 - Privilege Escalation
CVSS 6.5
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
CVSS 7.2
Craft CMS 5.6.0-5.9.14 save-permissions - Missing Authorization
Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutations
Craft CMS resource-js Endpoint - Server-Side Request Forgery
Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior
CVSS 7.2
Craft CMS < 4.17.8 and 5.9.14 - Private Asset IDOR
CVSS 6.5
Craft CMS 4.x and 5.x - Unauthenticated Config Sync Operations
CVSS 6.5
Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform URL
CVSS 5.3
Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users
CVSS 4.3
Craft CMS 5.3.0-5.9.13 - Entry Section Move Authorization Bypass
CVSS 6.5
Craft CMS Vulnerable to Stored XSS in Revision Context Menu
CVSS 5.4
Amazon S3 for Craft CMS 2.0.2-2.2.4 - Bucket Listing Information Disclosure
Craft CMS Google Cloud Storage <2.2.1 - Bucket List Disclosure
Azure Blob Storage for Craft CMS Potential Sensitive Information Disclosure vulnerability
RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugin
Craft CMS < 4.17.5 and 5.9.11 - AssetsController Path Traversal File Deletion
CVSS 4.3
Craft CMS vulnerable to behavior injection RCE via EntryTypesController
CVSS 7.2
Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController
CVSS 7.2
Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()
CVSS 9.8
Craft CMS 5.x < 5.9.9 and 4.x < 4.17.4 - Authenticated Remote Code Execution
CVSS 8.8
Craft CMS 5.0.1-5.9.8 - Authenticated SQL Injection via ElementSearchController
CVSS 8.8
Craft CMS 4.0.0-4.17.3 - Cross-Site Request Forgery via Preview Token Endpoint
CVSS 4.3
Craft CMS 5.8.21 - Authenticated RCE
CVSS 7.2
Craft CMS <4.17.0-beta.1/5.9.0-beta.1 - Info Disclosure
CVSS 7.5