Security: craftcms/cms
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Missing Authorization Check on User Group Removal via save-permissions ActionGHSA-jq2f-59pj-p3m3 published
Apr 13, 2026 by angrybradModerate -
Server-Side Request Forgery (SSRF) in Craft CMS with Asset Uploads MutationsGHSA-3m9m-24vh-39wx published
Apr 13, 2026 by angrybradModerate -
Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section permissionsGHSA-f582-6gf6-gx4g published
Mar 24, 2026 by angrybradModerate -
Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized usersGHSA-vgjg-248p-rfm2 published
Mar 24, 2026 by angrybradLow -
Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadataGHSA-44px-qjjc-xrhq published
Mar 24, 2026 by angrybradLow -
Anonymous "generate transform" calls for assets can expose private assets via transform URLGHSA-5pgf-h923-m958 published
Mar 24, 2026 by angrybradModerate -
Low-privilege users could read private asset contents when editing an asset (IDOR)GHSA-3pvf-vxrv-hh9c published
Mar 24, 2026 by angrybradModerate -
Unauthenticated users could execute project configuration sync operations that should be restricted trusted usersGHSA-6mrr-q3pj-h53w published
Mar 24, 2026 by angrybradModerate -
Host header injection leads to SSRF via resource-js endpointGHSA-95wr-3f2v-v2wh published
Apr 13, 2026 by angrybradModerate -
Potential authenticated Remote Code Execution via malicious attached BehaviorGHSA-2fph-6v5w-89hh published
Mar 24, 2026 by angrybradHigh