Craft CMS
70%
Total Score
43
51
80
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-55794 craftcms/cms is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 5.9.0 - 5.10.0. | 5.9.0 - 5.10.0 | High |
CVE-2026-55793 craftcms/cms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 5.0.0-RC1 - 5.9.22. | 5.0.0-RC1 - 5.9.22 | Medium |
CVE-2026-55792 craftcms/cms is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 4.0.0-RC1 - 4.18.0 and 5.0.0-RC1 - 5.10.0. | 4.0.0-RC1 - 4.18.05.0.0-RC1 - 5.10.0 | Medium |
CVE-2026-55790 craftcms/cms is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in versions 5.0.0-RC1 - 5.9.22 and 4.0.0-RC1 - 4.17.15. | 4.0.0-RC1 - 4.17.155.0.0-RC1 - 5.9.22 | High |
CVE-2026-50282 craftcms/cms is vulnerable to Missing Authorization in versions 5.0.0-RC1 - 5.9.21 and 4.0.0-RC1 - 4.17.14. | 4.0.0-RC1 - 4.17.145.0.0-RC1 - 5.9.21 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~2.14.1 | — | — |
symfony/yaml Version ^5.1.8 | — | — |
voku/stringy Version ^6.4.0 | — | — |
yiisoft/yii2 Version ~2.0.39.3 | — | — |
true/punycode Version ^2.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant