Craft CMS是Craft CMS公司的一套内容管理系统(CMS)。 Craft CMS 5.0.0-RC1至5.10.6之前版本和4.0.0-RC1至4.18.2之前版本存在权限许可和访问控制问题漏洞,该漏洞源于elementId参数中的环境变量和秘密在Twig模板渲染前被插入,即使启用了Twig沙箱,可能导致经过身份验证的攻击者通过盲错误技术泄露环境变量和秘密,进而伪造会话、提升权限并窃取数据库、SMTP、API或blob存储凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72778 | 8.8 HIGH | Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config |
| CVE-2026-72781 | 8.8 HIGH | Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escape |
| CVE-2026-72780 | 6.5 MEDIUM | Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey |
| CVE-2026-72783 | 6.2 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContained |
| CVE-2026-72784 | 5.4 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 SSRF via GraphQL asset mutation |
| CVE-2026-72779 | 4.5 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 Arbitrary File Read via SplFileObject |
| CVE-2026-72785 | 4.3 MEDIUM | Craft CMS before 5.10.6 Authorization Bypass via structures/move-element |
No comments yet