craftcms/cms Security Analysis
craftcms/cms has 18 known security vulnerabilities in Packagist (PHP). Upgrade to version 5.10.7 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.
Actively Exploited
CISA has confirmed this package has vulnerabilities under active exploitation. Prioritize updating immediately.
Recommended safe version: 5.10.7
Upgrading to 5.10.7 or later resolves all 18 known vulnerabilities in craftcms/cms. Run: composer require craftcms/cms:^5.10.7
Is craftcms/cms in your project?
Check if you're affected and upgrade to 5.10.7 to stay secure.
Active Exploitation Warning
One or more vulnerabilities in this package are known to be actively exploited in the wild. Immediate action is recommended.
Vulnerabilities
18 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.
| CVE / GHSA | Severity | Affected | Fixed In |
|---|---|---|---|
| CVE-2024-56145 Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabled | CRITICAL | 5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+663 more) | 5.5.2, 4.13.2, 3.9.14 |
| CVE-2026-55791 Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs | CRITICAL | 5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+416 more) | 5.10, 4.18 |
| CVE-2026-28697 Craft CMS Vulnerable to Authenticated RCE via "craft.app.fs.write()" in Twig Templates | CRITICAL | 5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+370 more) | 5.9.0-beta.1, 4.17.0-beta.1 |
| CVE-2024-37843 Craft CMS SQL injection vulnerability via the GraphQL API endpoint | CRITICAL | 1.0.26.1, 1.2.0-alpha.2310, 1.2.0-alpha.2312, 1.2.0-alpha.2316 (+746 more) | No fix available |
| CVE-2023-41892 Craft CMS Remote Code Execution vulnerability | CRITICAL | 4.0.0, 4.0.0-RC1, 4.0.0-RC2, 4.0.0-RC3 (+73 more) | 4.4.15 |
| CVE-2026-72780 Craft CMS: Passkey login accepts replayed WebAuthn assertions | CRITICAL | 5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+173 more) | 5.10.5 |
| CVE-2019-15929 Craft CMS possibility of brute force attempts | CRITICAL | 1.0.26.1, 1.2.0-alpha.2310, 1.2.0-alpha.2312, 1.2.0-alpha.2316 (+474 more) | 3.1.7 |
| CVE-2026-55794 Craft CMS: Potential authenticated Remote Code Execution via referrer redirect | HIGH | 5.9.0, 5.9.1, 5.9.10, 5.9.11 (+20 more) | 5.10.0 |
| CVE-2026-31857 CraftCMS has an RCE vulnerability via relational conditionals in the control panel | HIGH | 5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+391 more) | 5.9.9, 4.17.4 |
| CVE-2026-72781 Craft CMS: Authenticated RCE through Twig sandbox escape | HIGH | 5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+428 more) | 5.10.7, 4.18.3 |
| CVE-2026-72778 Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass | HIGH | 5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+426 more) | 5.10.6, 4.18.2 |
| CVE-2026-25495 Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]` | HIGH | 5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+366 more) | 5.8.22, 4.16.18 |
| CVE-2026-31858 CraftCMS's `ElementSearchController` Affected by Blind SQL Injection | HIGH | 5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+152 more) | 5.9.9 |
| CVE-2025-68456 Unauthenticated Craft CMS users can trigger a database backup | HIGH | 5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+806 more) | 5.8.21, 4.16.17 |
| CVE-2026-32267 Craft CMS Vulnerable to Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken() | HIGH | 4.0.0, 4.0.0-RC1, 4.0.0-RC2, 4.0.0-RC3 (+392 more) | 4.17.6, 5.9.12 |
| CVE-2026-29069 Craft CMS has unauthenticated activation email trigger with potential user enumeration | HIGH | 5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+372 more) | 5.9.0-beta.2, 4.17.0-beta.2 |
| CVE-2026-25497 Craft CMS: GraphQL Asset Mutation Privilege Escalation | HIGH | 5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+370 more) | 5.9.0-beta.1, 4.17.0-beta.1 |
| CVE-2025-68454 Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI | MEDIUM | 5.0.0, 5.0.0-RC1, 5.0.1, 5.0.2 (+364 more) | 5.8.21, 4.16.17 |
About This Data
Vulnerability data for craftcms/cms is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.
CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Related Packagist (PHP) Packages
Other packages in this ecosystem, ranked by shared vulnerabilities where available.
Check Your Dependencies
Scan your project to check if you're using a vulnerable version of craftcms/cms.