Craftcms Cms
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Craftcms Cms.
By the Year
In 2026 there have been 6 vulnerabilities in Craftcms Cms with an average score of 8.4 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 6 | 8.43 |
It may take a day or so for new Cms vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Craftcms Cms Security Vulnerabilities
OS Command Injection via accessCp Permission in Craft CMS
CVE-2026-79987
8.7 - High
- September 10, 2026
A remote, authenticated, non-admin Craft CMS Control Panel user with only the accessCp permission can execute operating system commands as the PHP web worker.
Reflection Injection
Craft CMS GraphQL Mutations Bypass Site Scope Filtering
CVE-2026-79991
7.1 - High
- September 02, 2026
Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schemas allowed sites. The query path (ElementResolverprepareElementQuery) correctly calls prepareArguments()`, so queries to unauthorized sites return empty. But mutations bypass this entirely an attacker with a token scoped to Site A can create, modify, or delete entries in Site B by passing siteId in the mutations argument.
SQL Injection
CraftCMS GraphQL Mutation SiteID Bypass via Unchecked Argument
CVE-2026-79990
8.7 - High
- September 02, 2026
Craft CMS GraphQL entry mutation resolvers (saveEntry, deleteEntry) read siteIddirectly from$argumentswithout passing throughArgumentManagerprepareArguments(), which is the function that enforces site-scope filtering via array_intersect against the GraphQL schemas allowed sites. The query path (ElementResolverprepareElementQuery) correctly calls prepareArguments()`, so queries to unauthorized sites return empty. But mutations bypass this entirely an attacker with a token scoped to Site A can create, modify, or delete entries in Site B by passing siteId in the mutations argument.
Insecure Direct Object Reference / IDOR
Drupal Authenticated Password Change Without Current Password
CVE-2026-79989
8.7 - High
- September 02, 2026
The vulnerability allows any authenticated user to change their own password without providing the current password or having an active elevated session. It also allows the attacker to change other users passwords if the attackers account has Edit users permission (which doesnt allow changing others passwords) and lacks Administrate users permission (which is required to change others passwords).
AuthZ
Authenticated RCE in Craft CMS via Twig Sandbox & Yii
CVE-2026-79988
8.7 - High
- August 27, 2026
The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading to authenticated RCE similar to previously disclosed vulnerabilities.
Protection Mechanism Failure
Craft CMS 4.x/5.x RCE via element-search config JSON cleanse bypass
CVE-2026-78416
8.7 - High
- August 24, 2026
Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in control panel element-search condition handling. A JSON cleanse bypass in condition.config allows Yii behavior/event configuration keys to be interpreted after decoding, enabling command execution as the PHP/web user.
Mass Assignment
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Craftcms Cms or by Craftcms? Click the Watch button to subscribe.