Showing 1 vulnerability on this page for CraftCMS

Signals CISA KEV Ransomware Nuclei
craftcms vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

CraftCMS 3 vCard Plugin 1.0.0 - Remote Code Execution

CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a crafted payload. Attackers can generate a malicious serialized payload that triggers remote code execution by exploiting the plugin's vCard download functionality with a specially crafted request.

CWE-502Feb 3, 2026
CVSS9.3v4.0EPSS0.615%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX