craftcms Vulnerabilities and Affected Products
Vulnerabilities associated with CraftCMS.
Products
Clear product- cms95 vulnerabilities
- commerce20 vulnerabilities
- craft_cms6 vulnerabilities
- Craft CMS2 vulnerabilities
- aws-s31 vulnerability
- azure-blob1 vulnerability
- CraftCMS1 vulnerability
- google-cloud1 vulnerability
- webhooks1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-37071CRITICAL | CraftCMS 3 vCard Plugin 1.0.0 - Remote Code ExecutionCraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code execution by exploiting the plugin's vCard download functionality with a specially crafted request. CWE-502Feb 3, 2026 | CVSS9.3v4.0 | EPSS0.615% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |