craftcms/cms is vulnerable to Information Disclosure
35
Low Risk
Affected versions of this package are vulnerable to information disclosure. Preview tokens are not properly validated or protected, which can allow unauthorized users to access draft or revision previews. This can lead to exposure of unpublished or sensitive content.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/cms is vulnerable to Information Disclosure in versions 3.5.0 - 4.17.2 and 5.0.0 - 5.9.6.
Upgrade the craftcms/cms library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant