Technology · Craft CMS
Craft CMS vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 46 vulnerabilities in Craft CMS: 0 in the last 7 days and 27 in the last 90 days, 6 of them critical and 5 exploited in the wild. The most recent, Craft CMS authenticated RCE through Twig sandbox escape, was published on 11 August 2026.
- Last 7 days
- 0
- Last 90 days
- 27
- Critical, all time
- 6
- Exploited in the wild
- 5
About Craft CMS
A flexible, user-friendly content management system for developers, designers, and content managers.
Latest Craft CMS vulnerabilities
- Craft CMS authenticated RCE through Twig sandbox escapehighCVSS 8.8
- Craft CMS authenticated environment variable leak in Twig templatingmediumCVSS 6.5
- Craft CMS path traversal in ensurePathIsContainedmediumCVSS 6.2
- Craft CMS authenticated RCE via condition.config JSON cleanse bypasshighCVSS 8.8
- Craft CMS authentication bypass via WebAuthn replay in passkey logincriticalCVSS 9.1
- Craft CMS arbitrary file read via SplFileObject in Twig templatesmediumCVSS 6.9
- Craft CMS environment variable leak via Twig sandbox bypassmediumCVSS 5.1
- Craft CMS authorization bypass in category structure managementmediumCVSS 5.3
- Craft CMS path traversal in Local file system classlowCVSS 2.1
- Craft CMS stored XSS via unescaped draft name in control panelmediumCVSS 5.1
- Craft CMS Twig sandbox escape leading to authenticated RCEhighCVSS 8.7
- Craft CMS authenticated RCE via condition.config JSON cleanse bypasshighCVSS 8.7
- Craft CMS RCE via event handler injection in FieldsControllerhighCVSS 8.6
- Craft CMS path traversal in assets/iconlowCVSS 2
- Craft CMS missing authorization in assets/preview-thumb endpointmediumCVSS 5.3
- Craft CMS improper authorization in GlobalsController reorder-sets endpointmediumCVSS 4.3
- Craft CMS authorization bypass in Charts EndpointmediumCVSS 4.3
- CVE-2026-14793: Craft CMS authorization bypass in GlobalsController reorder-setsmediumCVSS 4.3EPSS 0.2%
- CVE-2026-50282: Craft CMS authorization bypass in AssetsController folder movehighCVSS 4.9
- CVE-2026-50281: Craft CMS mass assignment in bulk-duplicate element actionhighCVSS 7.1
- CVE-2026-55792: Craft CMS sensitive file disclosure via dataUrl Twig functionmediumCVSS 6EPSS 0.3%
- CVE-2026-50280: Craft CMS authorization bypass in EntriesController move-to-sectionmediumCVSS 6EPSS 0.3%
- CVE-2026-50279: Craft CMS authorship spoofing in EntriesControllerhighCVSS 7.6EPSS 0.3%
- CVE-2026-55790: Craft CMS DOM XSS in CraftSupport widget via GitHub issue titleshighCVSS 7.4EPSS 0.3%
- CVE-2026-50284: Craft CMS authorization bypass in AssetsController folder deletionhighCVSS 7.1EPSS 0.3%
Most severe Craft CMS vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-32432: Craft CMS remote code execution via code injectioncriticalexploited in the wildCVSS 10EPSS 92.7%
- CVE-2024-56145: Craft CMS code injection in PHP register_argc_argv configurationcriticalexploited in the wildCVSS 9.8EPSS 94.2%
- CVE-2024-58136: Yiiframework Yii Improper Protection of Alternate Path Vulnerabilitycriticalexploited in the wildCVSS 9.8
- CVE-2025-23209: Craft CMS Code Injection Vulnerabilitycriticalexploited in the wildCVSS 8.1
- CVE-2025-35939: Craft CMS arbitrary code injection in session filescriticalexploited in the wildCVSS 5.3EPSS 33.1%
- Craft CMS authentication bypass via WebAuthn replay in passkey logincriticalCVSS 9.1
- Craft CMS authenticated RCE through Twig sandbox escapehighCVSS 8.8
- Craft CMS authenticated RCE via condition.config JSON cleanse bypasshighCVSS 8.8
- Craft CMS Twig sandbox escape leading to authenticated RCEhighCVSS 8.7
- Craft CMS authenticated RCE via condition.config JSON cleanse bypasshighCVSS 8.7
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 9 | 0 | |
| 6 Jul 2026 | 6 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 8 | 1 | |
| 10 Aug 2026 | 4 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/craft-cms.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Craft CMS vulnerabilities", https://junglewise.ai/threats/technologies/craft-cms, 26 September 2026.