15 Total CVEs
15 AI Analyzed
1 CISA KEV
3 Critical

Profile

6.7% ended up actively exploited 1 of 15 added to CISA KEV
20% rated critical (CVSS 9.0+) 3 critical, 12 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

15 CVEs in the last 12 months

Products

  • CMS10
  • Craft CMS2
  • code through1

3 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-15 of 15 CVEs
CVE-2026-84801
Analyzed
8.8
craftcms CMS

Craft CMS versions before 5.10.11 fail to validate admin status in the actionGetPasswordResetUrl endpoint, allowing non-admin users with administrateU...

2026-09-03
CVE-2026-84796
Analyzed
8.8
craftcms CMS

Craft CMS versions before 5.10.11 contain a site scope bypass vulnerability in GraphQL entry mutation resolvers that fail to validate siteId through A...

2026-09-03
CVE-2026-84795
Analyzed
9.8
craftcms CMS

Craft CMS versions prior to 5.10.11 contain an improper privilege management flaw that allows unauthenticated attackers to inherit administrator privi...

2026-09-03
CVE-2026-79990
Analyzed
8.7
craftcms CMS

Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArg...

2026-09-03
CVE-2026-79989
Analyzed
8.7
craftcms CMS

The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated sessi...

2026-09-03
CVE-2026-79988
Analyzed
8.7
craftcms CMS

The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to...

2026-08-28
CVE-2026-78416
Analyzed
8.7
craftcms CMS

Craft CMS versions from 4

2026-08-25
CVE-2026-72781
Analyzed
8.8
craftcms CMS

Craft CMS versions >= 5

2026-08-12
CVE-2026-72778
Analyzed
8.8
craftcms CMS

Craft CMS versions from 4

2026-08-12
CVE-2026-56382
Analyzed
7.2
craftcms CMS

Craft CMS (composer package craftcms/cms) versions >= 5

2026-06-22
CVE-2026-55794
Analyzed
8.7
craftcms Craft CMS

Craft CMS is a content management system (CMS)

2026-07-02
CVE-2026-29174
Analyzed
8.8
craftcms Multiple Products

Craft Commerce is an ecommerce platform for Craft CMS

2026-03-12
CVE-2026-29172
Analyzed
8.8
craftcms Multiple Products

Craft Commerce is an ecommerce platform for Craft CMS

2026-03-12
CVE-2025-32432
KEV Analyzed
9.5
craftcms Craft CMS

Craft CMS Code Injection Vulnerability - Active in CISA KEV catalog.

2026-03-21
CVE-2020-37071
Analyzed
9.8
craftcms code through

CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vulnerability that allows unauthenticated attackers to execute arbitrary PHP code through a c...

2026-02-04