craftcms/cms is vulnerable to Server-Side Request Forgery (SSRF)
80
High Risk
Affected versions of this package contain multiple undisclosed server-side request forgery (SSRF) and server-side template injection (SSTI) vulnerabilities. These issues may allow attackers to influence server-side request handling or template rendering logic in unexpected ways, potentially leading to unauthorized network access, information disclosure, or further impact depending on application configuration.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/cms is vulnerable to Server-Side Request Forgery (SSRF) in versions 3.5.0 - 4.16.19 and 5.0.0 - 5.8.23.
Upgrade the craftcms/cms library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant