CraftCMS cms是CraftCMS的内容管理系统。 CraftCMS CMS 4.0.0-RC1版本至4.17.7版本和5.0.0-RC1版本至5.9.13版本存在授权问题漏洞,该漏洞源于assets/preview-thumb端点缺少授权检查,可能导致控制面板用户无需查看目标私有资产的权限,通过调用端点并使用攻击者控制的assetId获取包含私有资产预览链接的HTML。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56382 | 7.2 HIGH | Craft CMS - Remote Code Execution via Missing Config Sanitization in FieldsController |
| CVE-2026-56394 | 6.5 MEDIUM | Craft CMS - Authenticated Path Traversal in assets/icon Extension Parameter |
| CVE-2026-56381 | 4.8 MEDIUM | Craft CMS - Stored XSS via User Group Name in User Permissions Page |
| CVE-2026-56383 | 4.8 MEDIUM | Craft CMS - Stored XSS in Table Field via Row Heading Column Type |
| CVE-2026-56393 | 4.8 MEDIUM | Craft CMS - Multiple Stored Cross-Site Scripting in Settings Names and Field Options |
| CVE-2026-56385 | 4.3 MEDIUM | Craft CMS - Authorization Bypass in assets/preview-file Endpoint |
No comments yet