Craft CMS是Craft CMS公司的一套内容管理系统(CMS)。 Craft CMS 5.0.0-RC1版本至5.10.7之前版本和4.0.0-RC1版本至4.18.3之前版本存在处理逻辑错误漏洞,该漏洞源于Twig沙箱机制中Craft将ElementInterface标记为安全且沙箱白名单扩展至整个类层次结构,即使启用Twig沙箱,经过身份验证且具有控制面板访问权限的攻击者也可渲染恶意Twig模板,滥用yii\base\Component任意函数调用小工具执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-72778 | 8.8 HIGH | Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config |
| CVE-2026-72780 | 6.5 MEDIUM | Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey |
| CVE-2026-72782 | 6.5 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leak |
| CVE-2026-72783 | 6.2 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContained |
| CVE-2026-72784 | 5.4 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutation |
| CVE-2026-72779 | 4.5 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 Arbitrary File Read via SplFileObject |
| CVE-2026-72785 | 4.3 MEDIUM | Craft CMS before 5.10.6 Authorization Bypass via structures/move-element |
No comments yet