CraftCMS cms是CraftCMS的内容管理系统。 Craft CMS存在跨站脚本漏洞,该漏洞源于editableTable.twig组件对行标题默认值输入清理不足,可能导致具有管理员账户的攻击者在其他用户查看受影响表格字段页面时注入任意JavaScript。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56382 | 7.2 HIGH | Craft CMS - Remote Code Execution via Missing Config Sanitization in FieldsController |
| CVE-2026-56394 | 6.5 MEDIUM | Craft CMS - Authenticated Path Traversal in assets/icon Extension Parameter |
| CVE-2026-56381 | 4.8 MEDIUM | Craft CMS - Stored XSS via User Group Name in User Permissions Page |
| CVE-2026-56393 | 4.8 MEDIUM | Craft CMS - Multiple Stored Cross-Site Scripting in Settings Names and Field Options |
| CVE-2026-56384 | 4.3 MEDIUM | Craft CMS - Missing Authorization in assets/preview-thumb Endpoint |
| CVE-2026-56385 | 4.3 MEDIUM | Craft CMS - Authorization Bypass in assets/preview-file Endpoint |
No comments yet