Craft CMS
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-44012 craftcms/cms is vulnerable to Missing Authorization in versions 5.0.0-RC1 - 5.9.18. | 5.0.0-RC1 - 5.9.18 | High |
CVE-2026-44011 craftcms/cms is vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') in versions 4.0.0 - 4.17.12 and 5.0.0 - 5.9.18. | 4.0.0 - 4.17.125.0.0 - 5.9.18 | High |
CVE-2026-44010 craftcms/cms is vulnerable to Missing Authorization in versions 5.0.0 - 5.9.18 and 4.0.0 - 4.17.12. | 4.0.0 - 4.17.125.0.0 - 5.9.18 | High |
AIKIDO-2026-10546 craftcms/cms is vulnerable to Authorization Bypass in versions 4.0.0 - 4.17.13 and 5.0.0 - 5.9.20. | 4.0.0 - 4.17.135.0.0 - 5.9.20 | High |
AIKIDO-2026-10550 craftcms/cms is vulnerable to Authorization Bypass in versions 0.0.1 - 4.17.13 and 5.0.0 - 5.9.20. | 0.0.1 - 4.17.135.0.0 - 5.9.20 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~2.14.1 | — | — |
symfony/yaml Version ^5.1.8 | — | — |
voku/stringy Version ^6.4.0 | — | — |
yiisoft/yii2 Version ~2.0.39.3 | — | — |
true/punycode Version ^2.1.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant