CVE-2026-79987Low-privilege RCE through element-search eager loading Exploitation status Not known exploited Fix YesAffected product C cms Published 09/10/2026 Severity High CVE-2026-86732Craft CMS before 5.10.12 Remote Code Execution via element-index Exploitation status Not known exploited Fix YesAffected product C cms Published 09/08/2026 Severity High CVE-2026-86731Craft CMS 5.0.0-RC1 before 5.10.12 Permission Escalation via UsersController Exploitation status Not confirmed Fix YesAffected product C cms Published 09/08/2026 Severity High CVE-2026-86730Craft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCE Exploitation status Not known exploited Fix YesAffected product C cms Published 09/08/2026 Severity High CVE-2026-79991Authenticated SQL Injection via nested eager-loading criteria Exploitation status Not known exploited Fix YesAffected product C cms Published 09/02/2026 Severity High CVE-2026-79990GQL entry mutation `siteId` bypasses schema site scope, enabling cross-site content read/write/delete Exploitation status Not known exploited Fix YesAffected product C cms Published 09/02/2026 Severity High CVE-2026-79989Arbitrary user password reset leading to administrator account takeover Exploitation status Not known exploited Fix YesAffected product C cms Published 09/02/2026 Severity High CVE-2026-84802Craft CMS 5.7.0 before 5.10.12 Information Disclosure via AssetsController Exploitation status Public exploit Fix YesAffected product C cms Published 09/02/2026 Severity Medium CVE-2026-84801Craft CMS 5.0.0-RC1 before 5.10.11 Authentication Bypass via administrateUsers Exploitation status Not known exploited Fix YesAffected product C cms Published 09/02/2026 Severity High CVE-2026-84800Craft CMS 5.0.0-RC1 before 5.10.11 File Overwrite via assets/replace-file Exploitation status Not known exploited Fix YesAffected product C cms Published 09/02/2026 Severity High CVE-2026-84799Craft CMS before 5.11.0 PII Disclosure via GraphQL User Relations Exploitation status Not known exploited Fix YesAffected product C cms Published 09/02/2026 Severity Medium CVE-2026-84798Craft CMS before 5.10.11 Authorization Bypass via actionDeleteForSite Exploitation status Not known exploited Fix YesAffected product C cms Published 09/02/2026 Severity High CVE-2026-84797Craft CMS 5.0.0-RC1 before 5.10.11 Authorization Bypass via actionDuplicate Exploitation status Not known exploited Fix YesAffected product C cms Published 09/02/2026 Severity Medium CVE-2026-84796Craft CMS 5.0.0-RC1 before 5.10.11 GraphQL Entry Mutation Site Scope Bypass Exploitation status Not known exploited Fix YesAffected product C cms Published 09/02/2026 Severity High CVE-2026-84795Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance Exploitation status Not known exploited Fix YesAffected product C cms Published 09/02/2026 Severity Critical CVE-2026-84794Craft CMS 5.0.0 through 5.10.10 Authorization Bypass via assets/move-asset Exploitation status Not known exploited Fix YesAffected product C cms Published 09/02/2026 Severity High CVE-2026-84793Craft CMS 5.0.0-RC1 before 5.10.11 Stored XSS via site name Exploitation status Public exploit Fix YesAffected product C cms Published 09/02/2026 Severity Medium CVE-2026-84792Craft CMS before 5.10.11 Broken Access Control via element-indexes Exploitation status Not known exploited Fix YesAffected product C cms Published 09/02/2026 Severity Medium CVE-2026-79988Authenticated RCE through Twig sandbox escape Exploitation status Not known exploited Fix YesAffected product C cms Published 08/27/2026 Severity High CVE-2026-78416Authenticated RCE via `condition.config` JSON cleanse bypass Exploitation status Not known exploited Fix YesAffected product C cms Published 08/24/2026 Severity High CVE-2026-72787Craft CMS 5.0.0-RC1 before 5.10.8 Stored XSS via Draft Name Exploitation status Not known exploited Fix YesAffected product C cms Published 08/12/2026 Severity Medium CVE-2026-72786Craft CMS 5.0.0-RC1 before 5.10.8 Authentication Bypass via Password Reset Exploitation status Not known exploited Fix YesAffected product C cms Published 08/12/2026 Severity High CVE-2026-72785Craft CMS before 5.10.6 Authorization Bypass via structures/move-element Exploitation status Not known exploited Fix YesAffected product C cms Published 08/11/2026 Severity Critical CVE-2026-72784Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutation Exploitation status Not known exploited Fix YesAffected product C cms Published 08/11/2026 Severity Medium CVE-2026-72783Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContained Exploitation status Not known exploited Fix YesAffected product C cms Published 08/11/2026 Severity Medium CVE-2026-72782Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leak Exploitation status Not known exploited Fix YesAffected product C cms Published 08/11/2026 Severity High CVE-2026-72781Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escape Exploitation status Not known exploited Fix YesAffected product C cms Published 08/11/2026 Severity High CVE-2026-72780Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey Exploitation status Not known exploited Fix YesAffected product C cms Published 08/11/2026 Severity High CVE-2026-72779Craft CMS 5.0.0-RC1 before 5.10.6 Arbitrary File Read via SplFileObject Exploitation status Not known exploited Fix YesAffected product C cms Published 08/11/2026 Severity High CVE-2026-72778Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config Exploitation status Not known exploited Fix YesAffected product C cms Published 08/11/2026 Severity High CVE-2026-50282Craft CMS: Unauthorized Deletion of Destination Folders During Forced Moves Exploitation status Not known exploited Fix YesAffected product C cms Published 07/02/2026 Severity Medium CVE-2026-50281Craft CMS: Mass assignment via id in newAttributes during bulk duplicate overwrites existing elements Exploitation status Not known exploited Fix YesAffected product C cms Published 07/02/2026 Severity High CVE-2026-50280Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check Exploitation status Not known exploited Fix YesAffected product C cms Published 07/01/2026 Severity Medium CVE-2026-50279Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap Exploitation status Public exploit Fix YesAffected product C cms Published 07/01/2026 Severity High CVE-2026-55794Craft CMS: Potential authenticated Remote Code Execution via referrer redirect Exploitation status Not known exploited Fix YesAffected product C cms Published 07/01/2026 Severity High CVE-2026-55792Craft CMS: Sensitive File Disclosure / Server-Side File Read Exploitation status Public exploit Fix YesAffected product C cms Published 07/01/2026 Severity Medium CVE-2026-55791Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs Exploitation status Not known exploited Fix YesAffected product C cms Published 07/01/2026 Severity Medium CVE-2026-55790Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget Exploitation status Not known exploited Fix YesAffected product C cms Published 07/01/2026 Severity High CVE-2026-50284Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets Exploitation status Not known exploited Fix YesAffected product C cms Published 07/01/2026 Severity High CVE-2026-50283Craft CMS: Unauthorized Deletion of Source Assets During File Replacement Exploitation status Not known exploited Fix YesAffected product C cms Published 07/01/2026 Severity Medium CVE-2026-55793Craft CMS: Stored XSS via Structure entry title in table view Exploitation status Public exploit Fix YesAffected product C cms Published 07/01/2026 Severity Medium CVE-2026-56394Craft CMS - Authenticated Path Traversal in assets/icon Extension Parameter Exploitation status Not known exploited Fix YesAffected product C cms Published 06/21/2026 Severity High CVE-2026-56393Craft CMS - Multiple Stored Cross-Site Scripting in Settings Names and Field Options Exploitation status Public exploit Fix YesAffected product C cms Published 06/21/2026 Severity Medium CVE-2026-56385Craft CMS - Authorization Bypass in assets/preview-file Endpoint Exploitation status Not known exploited Fix YesAffected product C cms Published 06/21/2026 Severity Medium CVE-2026-56384Craft CMS - Missing Authorization in assets/preview-thumb Endpoint Exploitation status Not known exploited Fix YesAffected product C cms Published 06/21/2026 Severity Medium CVE-2026-56383Craft CMS - Stored XSS in Table Field via Row Heading Column Type Exploitation status Public exploit Fix YesAffected product C cms Published 06/21/2026 Severity Medium CVE-2026-56382Craft CMS - Remote Code Execution via Missing Config Sanitization in FieldsController Exploitation status Public exploit Fix YesAffected product C cms Published 06/21/2026 Severity High CVE-2026-56381Craft CMS - Stored XSS via User Group Name in User Permissions Page Exploitation status Public exploit Fix YesAffected product C cms Published 06/21/2026 Severity Medium CVE-2026-44011Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior Exploitation status Public exploit Fix YesAffected product C cms Published 05/12/2026 Severity High CVE-2026-44012Craft CMS: Missing Volume Permission Check in AssetsController::actionShowInFolder Allows Information Disclosure Exploitation status Not known exploited Fix YesAffected product C cms Published 05/12/2026 Severity High CVE-2026-44010Craft CMS: Missing Authorization in GraphQL Address Resolver Allows Cross-Scope PII Disclosure Exploitation status Public exploit Fix YesAffected product C cms Published 05/12/2026 Severity High CVE-2026-41130Craft CMS has a host header injection leading to SSRF via resource-js endpoint Exploitation status Public exploit Fix Not confirmed Affected product C cms Published 04/21/2026 Severity Medium CVE-2026-41129Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutations Exploitation status Not known exploited Fix Not confirmed Affected product C cms Published 04/21/2026 Severity Medium CVE-2026-41128Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action Exploitation status Not known exploited Fix Not confirmed Affected product C cms Published 04/21/2026 Severity Medium CVE-2026-32272Craft Commerce: Blind SQL Injection via hasVariant/hasProduct Exploitation status Not known exploited Fix YesAffected product C commerce Published 04/13/2026 Severity High CVE-2026-32271Craft Commerce: SQL Injection can lead to Remote Code Execution via TotalRevenue Widget Exploitation status Not known exploited Fix YesAffected product C commerce Published 04/13/2026 Severity High CVE-2026-32270Craft Commerce: Unauthenticated information disclosure in `commerce/payments/pay` can leak some customer order data on anonymous payments Exploitation status Not known exploited Fix YesAffected product C commerce Published 04/13/2026 Severity Low CVE-2026-33162Craft CMS: Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section permissions Exploitation status Not known exploited Fix YesAffected product C cms Published 03/24/2026 Severity Medium CVE-2026-33161Craft CMS: Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users Exploitation status Not known exploited Fix YesAffected product C cms Published 03/24/2026 Severity Low CVE-2026-33160Craft CMS: Anonymous "generate transform" calls for assets can expose private assets via transform URL Exploitation status Not known exploited Fix YesAffected product C cms Published 03/24/2026 Severity Low CVE-2026-33159Craft CMS: Unauthenticated users could execute project configuration sync operations that should be restricted trusted users Exploitation status Public exploit Fix YesAffected product C cms Published 03/24/2026 Severity Medium CVE-2026-33158Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR) Exploitation status Not known exploited Fix YesAffected product C cms Published 03/24/2026 Severity Medium CVE-2026-33157Craft CMS: Potential authenticated Remote Code Execution via malicious attached Behavior Exploitation status Not known exploited Fix YesAffected product C cms Published 03/24/2026 Severity High CVE-2026-33051Craft CMS Vulnerable to Stored XSS in Revision Context Menu Exploitation status Not known exploited Fix YesAffected product C cms Published 03/20/2026 Severity Medium CVE-2026-32268Azure Blob Storage for Craft CMS Potential Sensitive Information Disclosure vulnerability Exploitation status Not known exploited Fix Not confirmed Affected product A azure-blob Published 03/18/2026 Severity High CVE-2026-32266Google Cloud Storage for Craft CMS has an Information Disclosure Vulnerability Exploitation status Not known exploited Fix Not confirmed Affected product G google-cloud Published 03/18/2026 Severity Low CVE-2026-32265Amazon S3 for Craft CMS has an Information Disclosure vulnerability Exploitation status Not known exploited Fix Not confirmed Affected product A aws-s3 Published 03/18/2026 Severity Medium CVE-2026-32267Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken() Exploitation status Public exploit Fix YesAffected product C cms Published 03/16/2026 Severity High CVE-2026-32264Craft CMS vulnerable to behavior injection RCE ElementIndexesController and FieldsController Exploitation status Not known exploited Fix YesAffected product C cms Published 03/16/2026 Severity High CVE-2026-32263Craft CMS vulnerable to behavior injection RCE via EntryTypesController Exploitation status Not known exploited Fix YesAffected product C cms Published 03/16/2026 Severity High CVE-2026-32262Craft CMS has a Path Traversal Vulnerability in AssetsController Exploitation status Not known exploited Fix YesAffected product C cms Published 03/16/2026 Severity Medium CVE-2026-32261RCE via SSTI for users with permissions to access the Craft CMS Webhooks plugin Exploitation status Not known exploited Fix YesAffected product W webhooks Published 03/16/2026 Severity High CVE-2026-31867Craft Commerce has a Potential IDOR in Commerce carts Exploitation status Not known exploited Fix YesAffected product C commerce Published 03/11/2026 Severity Medium CVE-2026-31859Craft has Reflective XSS via incomplete return URL sanitization Exploitation status Not known exploited Fix YesAffected product C cms Published 03/11/2026 Severity Medium CVE-2026-31858CraftCMS's `ElementSearchController` Affected by Blind SQL Injection Exploitation status Not known exploited Fix Not confirmed Affected product C cms Published 03/11/2026 Severity High CVE-2026-31857CraftCMS has an RCE vulnerability via relational conditionals in the control panel Exploitation status Not known exploited Fix Not confirmed Affected product C cms Published 03/11/2026 Severity High CVE-2026-29177Craft Commerce has Stored XSS in Craft Commerce Order Details Slideout Exploitation status Not known exploited Fix YesAffected product C commerce Published 03/10/2026 Severity Low CVE-2026-29176Craft Commerce has Stored XSS in Inventory Location Name Exploitation status Not known exploited Fix YesAffected product C commerce Published 03/10/2026 Severity Medium CVE-2026-29175Multiple Stored XSS in Commerce Inventory Page Leading to Session Hijacking Exploitation status Public exploit Fix YesAffected product C commerce Published 03/10/2026 Severity High CVE-2026-29174Craft Commerce has a SQL Injection in Commerce Inventory Table Sorting Exploitation status Not known exploited Fix YesAffected product C commerce Published 03/10/2026 Severity High CVE-2026-29173Craft Commerce has Stored XSS while updating Order Status from Orders Table Exploitation status Not known exploited Fix YesAffected product C commerce Published 03/10/2026 Severity Low CVE-2026-29172Craft Commerce has a SQL Injection in Commerce Purchasables Table Sorting Exploitation status Public exploit Fix YesAffected product C commerce Published 03/10/2026 Severity High CVE-2026-29113Craft has a potential information disclosure vulnerability in preview tokens Exploitation status Not known exploited Fix YesAffected product C cms Published 03/10/2026 Severity Low CVE-2026-29069Craft has an unauthenticated activation email trigger with potential user enumeration Exploitation status Not known exploited Fix YesAffected product C cms Published 03/04/2026 Severity Medium CVE-2026-28784Craft is affected by potential authenticated Remote Code Execution via Twig SSTI Exploitation status Not known exploited Fix Not confirmed Affected product C cms Published 03/04/2026 Severity High CVE-2026-28783Craft has a Twig Function Blocklist Bypass Exploitation status Not known exploited Fix YesAffected product C cms Published 03/04/2026 Severity Critical CVE-2026-28782Craft has a Permission Bypass and IDOR in Duplicate Entry Action Exploitation status Public exploit Fix YesAffected product C cms Published 03/04/2026 Severity Medium CVE-2026-28781Craft Affected by Entries Authorship Spoofing via Mass Assignment Exploitation status Public exploit Fix YesAffected product C cms Published 03/04/2026 Severity High CVE-2026-28697Craft Affected by Authenticated RCE via "craft.app.fs.write()" in Twig Templates Exploitation status Public exploit Fix YesAffected product C cms Published 03/04/2026 Severity Critical CVE-2026-28696Craft affected by IDOR via GraphQL @parseRefs Exploitation status Not known exploited Fix YesAffected product C cms Published 03/04/2026 Severity High CVE-2026-28695Craft affected by authenticated RCE via Twig SSTI - create() function + Symfony Process gadget Exploitation status Not known exploited Fix YesAffected product C cms Published 03/04/2026 Severity High CVE-2026-27129Cloud Metadata SSRF Protection Bypass via IPv6 Resolution Exploitation status Not known exploited Fix Not confirmed Affected product C cms Published 02/24/2026 Severity Medium CVE-2026-27128Craft CMS's race condition in Token Service potentially allows for token usage greater than the token limit Exploitation status Not known exploited Fix Not confirmed Affected product C cms Published 02/24/2026 Severity Medium CVE-2026-27127Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding Exploitation status Public exploit Fix Not confirmed Affected product C cms Published 02/24/2026 Severity High CVE-2026-27126Craft CMS has Stored XSS in Table Field via "HTML" Column Type Exploitation status Public exploit Fix Not confirmed Affected product C cms Published 02/24/2026 Severity Medium CVE-2026-25498Craft has a potential authenticated Remote Code Execution via malicious attached Behavior Exploitation status Not known exploited Fix YesAffected product C cms Published 02/09/2026 Severity High CVE-2026-25497Craft has a GraphQL Asset Mutation Privilege Escalation Exploitation status Not known exploited Fix YesAffected product C cms Published 02/09/2026 Severity High CVE-2026-25496Craft has a stored XSS in Number Prefix & Suffix Fields Exploitation status Not known exploited Fix YesAffected product C cms Published 02/09/2026 Severity Medium CVE-2026-25495Craft has a SQL Injection in Element Indexes via criteria[orderBy] Exploitation status Not known exploited Fix YesAffected product C cms Published 02/09/2026 Severity High CVE-2026-25494Craft has a SSRF in GraphQL Asset Mutation via Alternative IP Notation Exploitation status Not known exploited Fix YesAffected product C cms Published 02/09/2026 Severity Medium