Craftcms Security Vulnerabilities (CVEs)

Track 32 security vulnerabilities affecting Craftcms products and software. Get instant email alerts when new CVEs are discovered, automated security monitoring, and patch guidance.

6 Critical
15 High
11 Medium
🔔 Get Alerts for Craftcms
CVE-2026-27127 6.3

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Craft CMS's GraphQL Asset mutation that allows DNS rebinding attacks. Attacke...

Feb 24, 2026
CVE-2026-27129 6.5

This CVE describes a Server-Side Request Forgery (SSRF) bypass vulnerability in Craft CMS. The SSRF validation in GraphQL Asset mutations fails to pro...

Feb 24, 2026
CVE-2026-25495 8.8

This CVE describes a SQL injection vulnerability in Craft CMS affecting the element-indexes/get-elements endpoint. Attackers with Control Panel access...

Feb 9, 2026
CVE-2026-25496 4.8

This stored cross-site scripting (XSS) vulnerability in Craft CMS allows attackers to inject malicious scripts into Number field prefixes/suffixes. Wh...

Feb 9, 2026
CVE-2026-25497 8.8

This CVE describes a privilege escalation vulnerability in Craft CMS's GraphQL API where authenticated users with write access to one asset volume can...

Feb 9, 2026
CVE-2026-25498 7.2

This is a Remote Code Execution vulnerability in Craft CMS that allows authenticated administrators to execute arbitrary system commands on the server...

Feb 9, 2026
CVE-2026-25491 4.8

CVE-2026-25491 is a stored cross-site scripting (XSS) vulnerability in Craft CMS that allows attackers to inject malicious scripts via Entry Type name...

Feb 9, 2026
CVE-2026-25492 6.5

This vulnerability in Craft CMS allows authenticated attackers with permission to use the save_images_Asset GraphQL mutation to bypass hostname valida...

Feb 9, 2026
CVE-2026-25493 6.5

This CVE describes a Server-Side Request Forgery (SSRF) vulnerability in Craft CMS where attackers can bypass SSRF protections by exploiting HTTP redi...

Feb 9, 2026
CVE-2026-25494 6.5

This vulnerability allows attackers to bypass IP address blocklists in Craft CMS by using alternative IP notations (hexadecimal, mixed) that aren't re...

Feb 9, 2026
CVE-2026-25522 4.8

A stored cross-site scripting (XSS) vulnerability in Craft Commerce allows attackers to inject malicious JavaScript into Shipping Zone fields. When ad...

Feb 3, 2026
CVE-2025-68436 6.5

This vulnerability allows authenticated users on Craft CMS installations to expose sensitive assets through maliciously crafted requests targeting use...

Jan 5, 2026
CVE-2025-68437 6.8

This SSRF vulnerability in Craft CMS allows attackers with GraphQL asset management permissions to force the server to fetch content from arbitrary in...

Jan 5, 2026
CVE-2025-68454 8.8

This vulnerability allows authenticated remote code execution in Craft CMS via Twig Server-Side Template Injection. Attackers with administrator acces...

Jan 5, 2026
CVE-2025-68455 7.2

This vulnerability allows authenticated remote code execution in Craft CMS when an attacker with administrator access uploads a malicious Behavior att...

Jan 5, 2026
CVE-2025-68456 9.1

Unauthenticated attackers can trigger database backup operations in vulnerable Craft CMS versions, potentially causing resource exhaustion or exposing...

Jan 5, 2026
CVE-2025-57811 7.2

This CVE describes a remote code execution vulnerability in Craft CMS via Twig Server-Side Template Injection (SSTI). Attackers can execute arbitrary ...

Aug 25, 2025
CVE-2025-54417 8.8

This vulnerability allows remote code execution in Craft CMS when attackers have a compromised security key and can create arbitrary files in the /sto...

Aug 9, 2025
CVE-2025-35939 5.3

CVE-2025-35939 is a session file injection vulnerability in Craft CMS where unauthenticated users can inject arbitrary content into server-side sessio...

May 7, 2025
CVE-2025-46731 7.2

This CVE describes a server-side template injection (SSTI) vulnerability in Craft CMS that could allow remote code execution. The vulnerability requir...

May 5, 2025
CVE-2025-32432 10.0

CVE-2025-32432 is a critical remote code execution vulnerability in Craft CMS that allows attackers to execute arbitrary code on affected servers. Thi...

Apr 25, 2025
CVE-2025-23209 8.0

This is a remote code execution vulnerability in Craft CMS versions 4 and 5 that allows attackers to execute arbitrary code on affected systems. The v...

Jan 18, 2025
CVE-2024-56145 9.8

CVE-2024-56145 is a critical remote code execution vulnerability in Craft CMS that allows attackers to execute arbitrary code on affected systems. Use...

Dec 18, 2024
CVE-2024-52291 8.4

CVE-2024-52291 is a path traversal vulnerability in CraftCMS that allows authenticated administrators to bypass local file system validation using a d...

Nov 13, 2024
CVE-2024-37843 9.8

CVE-2024-37843 is an unauthenticated SQL injection vulnerability in Craft CMS's GraphQL API endpoint. Attackers can execute arbitrary SQL commands wit...

Jun 25, 2024
CVE-2023-36260 7.5

The Feed Me plugin 4.6.1 for Craft CMS contains a denial of service vulnerability where remote attackers can submit crafted strings to Feed-Me Name an...

Jan 30, 2024
CVE-2023-41892 10.0

CVE-2023-41892 is a critical remote code execution vulnerability in Craft CMS that allows attackers to execute arbitrary code on affected systems. Thi...

Sep 13, 2023
CVE-2023-30179 7.2

CVE-2023-30179 is a Server-Side Template Injection vulnerability in CraftCMS that allows authenticated attackers to inject Twig templates into the Use...

Jun 13, 2023
CVE-2023-32679 7.2

This vulnerability in Craft CMS allows attackers with admin privileges to execute arbitrary code by uploading files with arbitrary extensions that get...

May 19, 2023
CVE-2023-30130 8.8

This vulnerability allows remote attackers to execute arbitrary code on CraftCMS servers through server-side template injection in the Section paramet...

May 12, 2023
CVE-2021-41824 8.8

CVE-2021-41824 is a CSV injection vulnerability in Craft CMS that allows attackers to inject malicious formulas into exported CSV files. When victims ...

Sep 30, 2021
CVE-2021-27903 9.8

CVE-2021-27903 is a remote code execution vulnerability in Craft CMS that allows attackers to execute arbitrary code on affected systems. This vulnera...

Jun 30, 2021

Why Monitor Craftcms Security Vulnerabilities?

Real-time CVE tracking: Our automated system monitors 32+ known vulnerabilities affecting Craftcms products and software packages. Stay ahead of emerging threats with instant email notifications when new security issues are discovered.

Automated security monitoring: Unlike manual CVE checking, FixTheCVE automatically scans your servers and detects vulnerable Craftcms packages in under 60 seconds. No agents required - completely agentless scanning that works across Craftcms deployments.

Free vulnerability database: Access detailed information about every Craftcms CVE including CVSS scores, severity ratings, affected versions, and actionable patch guidance. Filter by critical, high, medium, or low severity to prioritize your security remediation efforts.

🚀 Get Started in 60 Seconds

  • Register free account & add your servers
  • Run one-time scan or schedule automatic monitoring (every 1-24 hours)
  • Receive instant alerts when new Craftcms CVEs affect your systems
  • Access dashboard with severity breakdown & fix instructions
Start Monitoring Craftcms CVEs Free