CraftCMS cms是CraftCMS的内容管理系统。 CraftCMS cms存在跨站脚本漏洞,该漏洞源于条目标题清理与转义不当,可能导致作者级别的控制面板用户在条目标题中存储恶意JavaScript有效载荷,当管理员或其他用户拖动条目标题时触发执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-50284 | Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows | |
| CVE-2026-50280 | Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section sa | |
| CVE-2026-50279 | Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authori | |
| CVE-2026-50283 | Craft CMS: Unauthorized Deletion of Source Assets During File Replacement | |
| CVE-2026-55790 | Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget | |
| CVE-2026-55792 | Craft CMS: Sensitive File Disclosure / Server-Side File Read | |
| CVE-2026-55791 | Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in acti | |
| CVE-2026-55794 | Craft CMS: Potential authenticated Remote Code Execution via referrer redirect |
No comments yet