Vendor
Craft CMS vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 18 vulnerabilities in Craft CMS: 0 in the last 7 days and 9 in the last 90 days, 4 of them critical and 4 exploited in the wild. The most recent, Craft CMS path traversal in ensurePathIsContained, was published on 11 August 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 9
- Critical, all time
- 4
- Exploited in the wild
- 4
About Craft CMS
Craft CMS is a content management system developer focused on flexible, custom digital experiences.
Craft CMS technologies
Latest Craft CMS vulnerabilities
- Craft CMS path traversal in ensurePathIsContainedmediumCVSS 6.2
- Craft CMS authenticated RCE through Twig sandbox escapehighCVSS 8.8
- Craft CMS authenticated environment variable leak in Twig templatingmediumCVSS 6.5
- Craft CMS authenticated RCE via condition.config JSON cleanse bypasshighCVSS 8.8
- Craft CMS path traversal in Local file system classlowCVSS 2.1
- Craft CMS authorization bypass in Charts EndpointmediumCVSS 4.3
- Craft CMS improper authorization in GlobalsController reorder-sets endpointmediumCVSS 4.3
- CVE-2026-14793: Craft CMS authorization bypass in GlobalsController reorder-setsmediumCVSS 4.3EPSS 0.4%
- CVE-2026-55792: Craft CMS sensitive file disclosure via dataUrl Twig functionmediumCVSS 4EPSS 0.4%
- Craft CMS path traversal in assets/icon endpointmediumCVSS 6.5
- Craft CMS missing authorization in assets preview endpointmediumCVSS 4.3
- Craft CMS authorization bypass in assets preview endpointmediumCVSS 4.3
- CVE-2026-31266: Pixel & Tonic Craft CMS missing authorization in migrate endpointinfoCVSS 6.5
- CVE-2026-44011: Craft CMS authenticated remote code execution in FieldLayouthighCVSS 4EPSS 0.4%
- CVE-2025-35939: Craft CMS stores arbitrary content provided by unauthenticated users in session filescriticalexploited in the wildCVSS 3.1EPSS 1.3%
- CVE-2025-32432: Craft CMS Allows Remote Code Executioncriticalexploited in the wildCVSS 3.1EPSS 99.8%
- CVE-2025-23209: Craft CMS has a potential RCE with a compromised security keycriticalexploited in the wildCVSS 3.1EPSS 21.8%
- CVE-2024-56145: Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabledcriticalexploited in the wildCVSS 3.1EPSS 97.4%
Most severe Craft CMS vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-32432: Craft CMS Allows Remote Code Executioncriticalexploited in the wildCVSS 3.1EPSS 99.8%
- CVE-2024-56145: Craft CMS has potential RCE when PHP `register_argc_argv` config setting is enabledcriticalexploited in the wildCVSS 3.1EPSS 97.4%
- CVE-2025-23209: Craft CMS has a potential RCE with a compromised security keycriticalexploited in the wildCVSS 3.1EPSS 21.8%
- CVE-2025-35939: Craft CMS stores arbitrary content provided by unauthenticated users in session filescriticalexploited in the wildCVSS 3.1EPSS 1.3%
- Craft CMS authenticated RCE through Twig sandbox escapehighCVSS 8.8
- Craft CMS authenticated RCE via condition.config JSON cleanse bypasshighCVSS 8.8
- CVE-2026-44011: Craft CMS authenticated remote code execution in FieldLayouthighCVSS 4EPSS 0.4%
- Craft CMS authenticated environment variable leak in Twig templatingmediumCVSS 6.5
- Craft CMS path traversal in assets/icon endpointmediumCVSS 6.5
- Craft CMS path traversal in ensurePathIsContainedmediumCVSS 6.2
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 3 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 1 | 0 | |
| 10 Aug 2026 | 4 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/craft-cms.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Craft CMS vulnerabilities", https://junglewise.ai/threats/vendors/craft-cms, 26 September 2026.