craftcms Vulnerabilities
CVE security advisories and vulnerability history for craftcms.
Overview
craftcms has 128 published CVE records since 2017, of which 4 are in CISA's Known Exploited Vulnerabilities catalog and 49 have a known public exploit. The average CVSS base score across scored CVEs is 6.5.
This page aggregates every publicly disclosed vulnerability (CVE) affecting craftcms products, with severity breakdowns, the most-affected products, the most common weakness types, and the latest disclosures.