CVE security advisories and vulnerability history for cms by craftcms.
102
Total CVEs
Published
4
In CISA KEV
Exploited in the wild
40
Public exploits
With known exploit
6.6
Avg CVSS
2017–2026
Last updated
Overview
craftcms cms has 102 published CVE records since 2017, of which 4 are in CISA's Known Exploited Vulnerabilities catalog and 40 have a known public exploit. The average CVSS base score across scored CVEs is 6.6.
This page aggregates every publicly disclosed vulnerability (CVE) affecting craftcms cms, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
Severity and exploitation
How the CVSS severity of craftcms cms's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
Critical6
High28
Medium38
Low5
25 additional CVEs have no CVSS severity score.
In CISA’s Known Exploited Vulnerabilities catalog
4
4 of craftcms cms's CVEs are confirmed exploited in the wild.
Public exploits
40
40 of craftcms cms's CVEs have a known public exploit available.
Affected versions and CVEs
Browse every craftcms cms version named in a CVE, then pick one to see only the CVEs that affect it.
Common questions about craftcms cms vulnerabilities.
How many CVEs does craftcms cms have?
craftcms cms has 102 published CVE records since 2017.
How many craftcms cms CVEs are in CISA KEV?
Yes — 4 of craftcms cms's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
Are there public exploits for craftcms cms vulnerabilities?
Yes — 40 of craftcms cms's CVEs have a known public exploit.
Which versions of craftcms cms are affected?
1,588 distinct craftcms cms versions are named across its CVEs. Use the version filter above to see the CVEs affecting a specific version.
What are the most common weakness types in craftcms cms CVEs?
craftcms cms's CVEs most often map to these CWE weakness types: CWE-79 (Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')), CWE-94 (Improper Control of Generation of Code ('Code Injection')), CWE-639 (Authorization Bypass Through User-Controlled Key), CWE-918 (Server-Side Request Forgery (SSRF)).
How many critical craftcms cms vulnerabilities are there?
craftcms cms has 6 critical and 28 high-severity CVEs.
What is the average severity of craftcms cms CVEs?
The average CVSS base score across craftcms cms's scored CVEs is 6.6.