Intel

AIKIDO-2026-10212

craftcms/cms is vulnerable to Information Disclosure

Information DisclosureGHSA-vg3j-hpm9-8v5v Published Feb 21, 2026

35

Low Risk

This Affects:

PHPcraftcms/cms
3.5.0 - 4.17.2
Fixed in 4.17.3
5.0.0 - 5.9.6
Fixed in 5.9.7
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to information disclosure. Preview tokens are not properly validated or protected, which can allow unauthorized users to access draft or revision previews. This can lead to exposure of unpublished or sensitive content.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

craftcms/cms is vulnerable to Information Disclosure in versions 3.5.0 - 4.17.2 and 5.0.0 - 5.9.6.

How to fix this

Upgrade the craftcms/cms library to the patch version.