Craftcms
craftcms
114 CVEs • 2 products
Products (2)
Click to collapseToggle
Products (2)
Click to collapse
CVEs (114)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller. |
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at an s/admin/entries/news/new URI. |
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them. |
Craft CMS before 3.3.8 has stored XSS via a name field. This field is mishandled during site deletion. |
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/geolocation data to the public. |
Craft CMS before 3.1.31 does not properly filter XML feeds and thus allowing XSS. |
Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.pa...Show more |
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab. |
Craft CMS 2.6.3000 allows remote attackers to execute arbitrary PHP code by using the "Assets->Upload files" screen and then the "Replace it" option, because this allows a .jpg file to have embedded PHP code, and then be...Show more |
Craft CMS before 2.6.2982 allows for a potential XSS attack vector by uploading a malicious SVG file. |
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message. |
Craft CMS before 2.6.2976 allows XSS attacks because an array returned by HttpRequestService::getSegments() and getActionSegments() need not be zero-based. NOTE: this vulnerability exists because of an incomplete fix for...Show more |
Craft CMS before 2.6.2976 does not properly restrict viewing the contents of files in the craft/app/ folder. |
Craft CMS before 2.6.2974 allows XSS attacks. |