Cms Craftcms Cms

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Craftcms Cms.

By the Year

In 2026 there have been 6 vulnerabilities in Craftcms Cms with an average score of 8.4 out of ten.

Year Vulnerabilities Average Score
2026 6 8.43

It may take a day or so for new Cms vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Craftcms Cms Security Vulnerabilities

OS Command Injection via accessCp Permission in Craft CMS
CVE-2026-79987 8.7 - High - September 10, 2026

A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.

Reflection Injection

Craft CMS GraphQL Mutations Bypass Site Scope Filtering
CVE-2026-79991 7.1 - High - September 02, 2026

Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schemas allowed sites. The query path (ElementResolverprepareElementQuery) correctly calls prepareArguments()`, so queries to unauthorized sites return empty. But mutations bypass this entirely an attacker with a token scoped to Site A can create, modify, or delete entries in Site B by passing siteId in the mutations argument.

SQL Injection

CraftCMS GraphQL Mutation SiteID Bypass via Unchecked Argument
CVE-2026-79990 8.7 - High - September 02, 2026

Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schemas allowed sites. The query path (ElementResolverprepareElementQuery) correctly calls prepareArguments()`, so queries to unauthorized sites return empty. But mutations bypass this entirely an attacker with a token scoped to Site A can create, modify, or delete entries in Site B by passing siteId in the mutations argument.

Insecure Direct Object Reference / IDOR

Drupal Authenticated Password Change Without Current Password
CVE-2026-79989 8.7 - High - September 02, 2026

The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users passwords if the attackers account has Edit users permission (which doesnt allow changing others passwords) and lacks Administrate users permission (which is required to change others passwords).

AuthZ

Authenticated RCE in Craft CMS via Twig Sandbox & Yii
CVE-2026-79988 8.7 - High - August 27, 2026

The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities.

Protection Mechanism Failure

Craft CMS 4.x/5.x RCE via element-search config JSON cleanse bypass
CVE-2026-78416 8.7 - High - August 24, 2026

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior/event configuration keys to be interpreted after decoding, enabling command execution as the PHP/web user.

Mass Assignment

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Craftcms Cms or by Craftcms? Click the Watch button to subscribe.

Craftcms
Vendor

Craftcms Cms
Product

subscribe