Craft CMS是Craft CMS公司的一套内容管理系统(CMS)。 Craft CMS 5.0.0-RC1版本至5.10.6之前版本和4.0.0-RC1版本至4.18.2之前版本存在输入验证错误漏洞,该漏洞源于create() Twig函数限制类实例化时阻止列表未包含SplFileObject,经过身份验证的管理员可在非沙盒模板环境中配置恶意条目类型标题或URI格式,实例化SplFileObject,导致服务器上的任意文件(如包含安全密钥和数据库凭据的.env文件)被读取并渲染为条目标题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72778 | 8.8 HIGH | Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config |
| CVE-2026-72781 | 8.8 HIGH | Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escape |
| CVE-2026-72780 | 6.5 MEDIUM | Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey |
| CVE-2026-72782 | 6.5 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leak |
| CVE-2026-72783 | 6.2 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContained |
| CVE-2026-72784 | 5.4 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutation |
| CVE-2026-72785 | 4.3 MEDIUM | Craft CMS before 5.10.6 Authorization Bypass via structures/move-element |
No comments yet