Technology · Packagist
craftcms/cms (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 27 vulnerabilities in craftcms/cms (Packagist): 0 in the last 7 days and 17 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, Craft CMS authenticated RCE through Twig sandbox escape, was published on 11 August 2026.
- Last 7 days
- 0
- Last 90 days
- 17
- Critical, all time
- 1
- Exploited in the wild
- 0
About craftcms/cms (Packagist)
A content management system built on Yii, Twig, and PostgreSQL/MySQL.
Latest craftcms/cms (Packagist) vulnerabilities
- Craft CMS authenticated RCE through Twig sandbox escapehighCVSS 8.8
- Craft CMS path traversal in ensurePathIsContainedmediumCVSS 6.2
- Craft CMS authorization bypass in category structure modificationmediumCVSS 4.3
- Craft CMS authenticated environment variable leak in Twig templatingmediumCVSS 6.5
- Craft CMS authenticated RCE via condition.config JSON cleanse bypasshighCVSS 8.8
- Craft CMS arbitrary file read via SplFileObject in template contextsmediumCVSS 4.5
- Craft CMS authentication bypass via WebAuthn replay in passkey logincriticalCVSS 9.1
- Craft CMS authorization bypass in category structure managementmediumCVSS 5.3
- Craft CMS stored XSS via unescaped draft name in control panelmediumCVSS 5.1
- Craft CMS improper authorization in user password resethighCVSS 0
- Craft CMS RCE via event handler injection in FieldsControllerhighCVSS 8.6
- Craft CMS improper authorization in GlobalsController reorder-sets endpointmediumCVSS 4.3
- CVE-2026-50281: Craft CMS mass assignment in bulk-duplicate element actionhighCVSS 7.1
- CVE-2026-55794: Craft CMS authenticated RCE via Twig injection in Referrer headerhighCVSS 8.7EPSS 0.3%
- CVE-2026-50280: Craft CMS authorization bypass in EntriesController move-to-sectionmediumCVSS 6EPSS 0.3%
- CVE-2026-50279: Craft CMS authorship spoofing in EntriesControllerhighCVSS 7.6EPSS 0.3%
- CVE-2026-55793: Craft CMS stored XSS in Structure entry title table viewmediumCVSS 5.9EPSS 0.4%
- Craft CMS path traversal in assets/icon endpointmediumCVSS 6.5
- Craft CMS stored XSS in settings names and field optionsmediumCVSS 4.8
- Craft CMS RCE in FieldsController via missing cleanseConfighighCVSS 7.2
- Craft CMS authorization bypass in assets preview endpointmediumCVSS 4.3
- Craft CMS stored XSS in User Permissions pagemediumCVSS 4.8
- Craft CMS stored XSS in Table field Row HeadingmediumCVSS 4.8
- Craft CMS missing authorization in assets preview endpointmediumCVSS 4.3
- CVE-2026-56381: Craft CMS stored XSS in User Permissions pagemediumCVSS 4.8EPSS 0.3%
Most severe craftcms/cms (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- Craft CMS authentication bypass via WebAuthn replay in passkey logincriticalCVSS 9.1
- Craft CMS authenticated RCE through Twig sandbox escapehighCVSS 8.8
- Craft CMS authenticated RCE via condition.config JSON cleanse bypasshighCVSS 8.8
- CVE-2026-55794: Craft CMS authenticated RCE via Twig injection in Referrer headerhighCVSS 8.7EPSS 0.3%
- Craft CMS RCE via event handler injection in FieldsControllerhighCVSS 8.6
- CVE-2026-50279: Craft CMS authorship spoofing in EntriesControllerhighCVSS 7.6EPSS 0.3%
- Craft CMS RCE in FieldsController via missing cleanseConfighighCVSS 7.2
- CVE-2026-50281: Craft CMS mass assignment in bulk-duplicate element actionhighCVSS 7.1
- CVE-2026-44012: Craft CMS missing volume permission check in AssetsControllerhighCVSS 7.1
- Craft CMS improper authorization in user password resethighCVSS 0
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 5 | 0 | |
| 6 Jul 2026 | 2 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 4 | 1 | |
| 10 Aug 2026 | 6 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/craftcms-cms.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "craftcms/cms (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/craftcms-cms, 26 September 2026.