Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
craft cms vulnerabilities and exploits
(subscribe to this query)
5.4
CVSSv3
CVE-2022-37250
Craft CMS 4.2.0.1 suffers from Stored Cross Site Scripting (XSS) in /admin/myaccount.
Craftcms Craft Cms 4.2.0.1
8.8
CVSSv3
CVE-2023-30130
An issue found in CraftCMS v.3.8.1 allows a remote malicious user to execute arbitrary code via a crafted script to the Section parameter.
Craftcms Craft Cms 3.8.1
4.8
CVSSv3
CVE-2023-33194
Craft is a CMS for creating custom digital experiences on the web.The platform does not filter input and encode output in Quick Post validation error message, which can deliver an XSS payload. Old CVE fixed the XSS in label HTML but didn’t fix it when clicking save. This is...
Craftcms Craft Cms
Craftercms Craftercms 4.0.0
8.8
CVSSv3
CVE-2018-8908
An issue exists in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to trick a victim into clicking on it; once executed, a malicious user will be created with admin privileges...
Frog Cms Project Frog Cms 0.9.5
1 EDB exploit
4.3
CVSSv3
CVE-2021-23266
An anonymous user can craft a URL with text that ends up in the log viewer as is. The text can then include textual messages to mislead the administrator.
Craftercms Crafter Cms
9.8
CVSSv3
CVE-2013-7455
Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x prior to 2.6 allows remote malicious users to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.
Littlecms Little Cms Color Engine 2.0
Littlecms Little Cms Color Engine 2.5
Littlecms Little Cms Color Engine 2.2
Littlecms Little Cms Color Engine 2.1
Littlecms Little Cms Color Engine 2.4
Littlecms Little Cms Color Engine 2.3
4.8
CVSSv3
CVE-2019-19903
An issue exists in Backdrop CMS 1.14.x prior to 1.14.2. It doesn't sufficiently filter output when displaying file type descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administrator execute scripting when vi...
Backdropcms Backdrop Cms
4.8
CVSSv3
CVE-2019-19900
An issue exists in Backdrop CMS 1.13.x prior to 1.13.5 and 1.14.x prior to 1.14.2. It doesn't sufficiently filter output when displaying content type names in the content creation interface. An attacker could potentially craft a specialized content type name, then have an ed...
Backdropcms Backdrop Cms
4.8
CVSSv3
CVE-2019-19901
An issue exists in Backdrop CMS 1.13.x prior to 1.13.5 and 1.14.x prior to 1.14.2. It doesn't sufficiently filter output when displaying certain block descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administ...
Backdropcms Backdrop Cms
4.9
CVSSv3
CVE-2022-23409
The Logs plugin prior to 3.0.4 for Craft CMS allows remote malicious users to read arbitrary files via input to actionStream in Controller.php.
Ethercreative Logs
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4654
CVE-2023-49606
encryption
NULL pointer dereference
CVE-2024-4439
CVE-2024-4649
race condition
CVE-2024-27202
CVE-2024-34566
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
NEXT »