craftcms Vulnerabilities and Affected Products
Vulnerabilities associated with Craft CMS.
Products
Clear product- cms95 vulnerabilities
- commerce20 vulnerabilities
- craft_cms6 vulnerabilities
- Craft CMS2 vulnerabilities
- aws-s31 vulnerability
- azure-blob1 vulnerability
- CraftCMS1 vulnerability
- google-cloud1 vulnerability
- webhooks1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-41892CRITICAL | Craft CMS Remote Code Execution vulnerabilityCraft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15. | CVSS10.0v3.1 | EPSS93.2% | PoCs8 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-9757CRITICAL | SEOmatic for CraftCMS allows Server-Side Template InjectionThe SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller. | CVSS9.8v3.1 | EPSS73.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |