A reactive Twig component framework for Craft.
98%
Total Score
95
100
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-27131 putyourlightson/craft-sprig is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 2.0.0 - 2.15.2 and 3.0.0 - 3.7.2. | 2.0.0 - 2.15.23.0.0 - 3.7.2 | Medium |
AIKIDO-2025-10242 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. putyourlightson/craft-sprig is vulnerable to Cross-site Scripting (XSS) in versions 2.0.0 - 2.13.1 and 3.0.0 - 3.5.2. | 2.0.0 - 2.13.13.0.0 - 3.5.2 | Low |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
craftcms/cms Version ^3.0.0 | — | — |
ivopetkov/html5-dom-document-php Version ^2.0.0 | — | — |
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant