Loading...
Skip to main content
Packagist (PHP)

craftcms/cms Security Analysis

craftcms/cms has 18 known security vulnerabilities in Packagist (PHP). Upgrade to version 5.10.7 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

18 Vulnerabilities

Actively Exploited

CISA has confirmed this package has vulnerabilities under active exploitation. Prioritize updating immediately.

Recommended safe version: 5.10.7

Upgrading to 5.10.7 or later resolves all 18 known vulnerabilities in craftcms/cms. Run: composer require craftcms/cms:^5.10.7

Is craftcms/cms in your project?

Check if you're affected and upgrade to 5.10.7 to stay secure.

18
Total
0
Critical
0
High
0
Medium
0
Low

Active Exploitation Warning

One or more vulnerabilities in this package are known to be actively exploited in the wild. Immediate action is recommended.

Vulnerabilities

18 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2024-56145
Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled
CRITICAL
5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+663 more)5.5.2, 4.13.2, 3.9.14
CVE-2026-55791
Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
CRITICAL
5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+416 more)5.10, 4.18
CVE-2026-28697
Craft CMS Vulnerable to Authenticated RCE via "craft.app.fs.write()" in Twig Templates
CRITICAL
5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+370 more)5.9.0-beta.1, 4.17.0-beta.1
CVE-2024-37843
Craft CMS SQL injection vulnerability via the GraphQL API endpoint
CRITICAL
1.0.26.1, 1.2.0-alpha.2310, 1.2.0-alpha.2312, 1.2.0-alpha.2316 (+746 more)No fix available
CVE-2023-41892
Craft CMS Remote Code Execution vulnerability
CRITICAL
4.0.0, 4.0.0-RC1, 4.0.0-RC2, 4.0.0-RC3 (+73 more)4.4.15
CVE-2026-72780
Craft CMS: Passkey login accepts replayed WebAuthn assertions
CRITICAL
5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+173 more)5.10.5
CVE-2019-15929
Craft CMS possibility of brute force attempts
CRITICAL
1.0.26.1, 1.2.0-alpha.2310, 1.2.0-alpha.2312, 1.2.0-alpha.2316 (+474 more)3.1.7
CVE-2026-55794
Craft CMS: Potential authenticated Remote Code Execution via referrer redirect
HIGH
5.9.0, 5.9.1, 5.9.10, 5.9.11 (+20 more)5.10.0
CVE-2026-31857
CraftCMS has an RCE vulnerability via relational conditionals in the control panel
HIGH
5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+391 more)5.9.9, 4.17.4
CVE-2026-72781
Craft CMS: Authenticated RCE through Twig sandbox escape
HIGH
5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+428 more)5.10.7, 4.18.3
CVE-2026-72778
Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
HIGH
5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+426 more)5.10.6, 4.18.2
CVE-2026-25495
Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`
HIGH
5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+366 more)5.8.22, 4.16.18
CVE-2026-31858
CraftCMS's `ElementSearchController` Affected by Blind SQL Injection
HIGH
5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+152 more)5.9.9
CVE-2025-68456
Unauthenticated Craft CMS users can trigger a database backup
HIGH
5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+806 more)5.8.21, 4.16.17
CVE-2026-32267
Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()
HIGH
4.0.0, 4.0.0-RC1, 4.0.0-RC2, 4.0.0-RC3 (+392 more)4.17.6, 5.9.12
CVE-2026-29069
Craft CMS has unauthenticated activation email trigger with potential user enumeration
HIGH
5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+372 more)5.9.0-beta.2, 4.17.0-beta.2
CVE-2026-25497
Craft CMS: GraphQL Asset Mutation Privilege Escalation
HIGH
5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+370 more)5.9.0-beta.1, 4.17.0-beta.1
CVE-2025-68454
Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI
MEDIUM
5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+364 more)5.8.21, 4.16.17

About This Data

Vulnerability data for craftcms/cms is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Related Packagist (PHP) Packages

Other packages in this ecosystem, ranked by shared vulnerabilities where available.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of craftcms/cms.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed