Craft CMS是Craft CMS公司的一套内容管理系统(CMS)。 Craft CMS 4.0.0-RC1版本至4.18.2之前版本和5.0.0-RC1版本至5.10.6之前版本存在输入验证错误漏洞,该漏洞源于控制面板元素搜索条件处理中对外部请求控制的条件数组清理不充分,Yii特殊配置键在JSON解码后未被重新清理,导致经过身份验证的攻击者可能以PHP/web用户身份执行操作系统命令。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-72781 | 8.8 HIGH | Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escape |
| CVE-2026-72780 | 6.5 MEDIUM | Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey |
| CVE-2026-72782 | 6.5 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leak |
| CVE-2026-72783 | 6.2 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContained |
| CVE-2026-72784 | 5.4 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutation |
| CVE-2026-72779 | 4.5 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 Arbitrary File Read via SplFileObject |
| CVE-2026-72785 | 4.3 MEDIUM | Craft CMS before 5.10.6 Authorization Bypass via structures/move-element |
No comments yet