Vulnerabilities (CVE)

Filtered by vendor Craftcms Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-41892 1 Craftcms 1 Craft Cms 2023-12-22 N/A 9.8 CRITICAL
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.
CVE-2021-27903 1 Craftcms 1 Craft Cms 2022-07-12 7.5 HIGH 9.8 CRITICAL
An issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did not restrict administrative changes (if an attacker were somehow able to hijack an administrator's session).
CVE-2020-9757 1 Craftcms 1 Craft Cms 2022-04-26 7.5 HIGH 9.8 CRITICAL
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.
CVE-2019-15929 1 Craftcms 1 Craft Cms 2019-10-30 5.0 MEDIUM 9.8 CRITICAL
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.