craftcms Vulnerabilities and Affected Products
Vulnerabilities associated with google-cloud.
Products
Clear product- cms95 vulnerabilities
- commerce20 vulnerabilities
- craft_cms6 vulnerabilities
- Craft CMS2 vulnerabilities
- aws-s31 vulnerability
- azure-blob1 vulnerability
- CraftCMS1 vulnerability
- google-cloud1 vulnerability
- webhooks1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
Google Cloud Storage for Craft CMS has an Information Disclosure VulnerabilityThe Google Cloud Storage for Craft CMS plugin provides a Google Cloud Storage integration for Craft CMS. In versions on the 2.x branch prior to 2.2.1, the `DefaultController->actionLoadBucketData()` endpoint allows unauthenticated users with a valid CSRF token to view a list of buckets that the plugin is allowed to see. Users should update to version 2.2.1 of the plugin to mitigate the issue. CWE-200Mar 18, 2026 | CVSS2.4v4.0 | EPSS0.344% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |