Craft CMS
100%
Total Score
100
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10280 New craftcms/cms is vulnerable to Privilege Escalation in versions 4.0.0 - 4.17.5 and 5.0.0 - 5.9.11. | 4.0.0 - 4.17.55.0.0 - 5.9.11 | High |
CVE-2026-28784 New craftcms/cms is vulnerable to Improper Neutralization of Special Elements Used in a Template Engine in versions 5.0.0-RC1 - 5.9.0-beta.1 and 4.0.0-RC1 - 4.17.0-beta.1. | 4.0.0-RC1 - 4.17.0-beta.15.0.0-RC1 - 5.9.0-beta.1 | Medium |
CVE-2026-28782 New craftcms/cms is vulnerable to Authorization Bypass Through User-Controlled Key in versions 5.0.0-RC1 - 5.9.0-beta.1 and 4.0.0-RC1 - 4.17.0-beta.1. | 4.0.0-RC1 - 4.17.0-beta.15.0.0-RC1 - 5.9.0-beta.1 | Medium |
CVE-2026-28783 New craftcms/cms is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 5.0.0-RC1 - 5.9.0-beta.1 and 4.0.0-RC1 - 4.17.0-beta.1. | 4.0.0-RC1 - 4.17.0-beta.15.0.0-RC1 - 5.9.0-beta.1 | Medium |
CVE-2026-28781 New craftcms/cms is vulnerable to Authorization Bypass Through User-Controlled Key in versions 5.0.0-RC1 - 5.9.0-beta.1 and 4.0.0-RC1 - 4.17.0-beta.1. | 4.0.0-RC1 - 4.17.0-beta.15.0.0-RC1 - 5.9.0-beta.1 | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
twig/twig Version ~2.14.1 | — | — |
symfony/yaml Version ^5.1.8 | — | — |
voku/stringy Version ^6.4.0 | — | — |
yiisoft/yii2 Version ~2.0.39.3 | — | — |
true/punycode Version ^2.1.1 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant