Craft CMS
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-33162 craftcms/cms is vulnerable to Improper Authorization in versions 5.3.0 - 5.9.13. | 5.3.0 - 5.9.13 | Medium |
CVE-2026-33161 craftcms/cms is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 5.0.0-RC1 - 5.9.13 and 4.0.0-RC1 - 4.17.7. | 4.0.0-RC1 - 4.17.75.0.0-RC1 - 5.9.13 | Low |
CVE-2026-33160 craftcms/cms is vulnerable to Authorization Bypass Through User-Controlled Key in versions 5.0.0-RC1 - 5.9.13 and 4.0.0-RC1 - 4.17.7. | 4.0.0-RC1 - 4.17.75.0.0-RC1 - 5.9.13 | Low |
CVE-2026-33159 craftcms/cms is vulnerable to Missing Authentication for Critical Function in versions 5.0.0-RC1 - 5.9.13 and 4.0.0-RC1 - 4.17.7. | 4.0.0-RC1 - 4.17.75.0.0-RC1 - 5.9.13 | Medium |
CVE-2026-33158 craftcms/cms is vulnerable to Authorization Bypass Through User-Controlled Key in versions 4.0.0-RC1 - 4.17.7 and 5.0.0-RC1 - 5.9.13. | 4.0.0-RC1 - 4.17.75.0.0-RC1 - 5.9.13 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~2.14.1 | — | — |
symfony/yaml Version ^5.1.8 | — | — |
voku/stringy Version ^6.4.0 | — | — |
yiisoft/yii2 Version ~2.0.39.3 | — | — |
true/punycode Version ^2.1.1 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant