Craft CMS是Craft CMS公司的一套内容管理系统(CMS)。 Craft CMS 5.0.0-RC1至5.10.6之前版本和4.0.0-RC1至4.18.2之前版本存在服务端请求伪造漏洞,该漏洞源于GraphQL save<Volume>Asset mutation存在服务端请求伪造,anti-SSRF验证不完整,validateIp()未覆盖CGNAT(100.64.0.0/10)和NAT64(64:ff9b::/96)范围,且IP检查在请求发出后才执行,可能导致具备资产创建权限的Graph
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-72778 | 8.8 HIGH | Craft CMS 5.0.0-RC1 before 5.10.6 Authenticated RCE via condition.config |
| CVE-2026-72781 | 8.8 HIGH | Craft CMS 5.0.0-RC1 before 5.10.7 Remote Code Execution via Twig Sandbox Escape |
| CVE-2026-72780 | 6.5 MEDIUM | Craft CMS before 5.10.5 WebAuthn Assertion Replay via login-with-passkey |
| CVE-2026-72782 | 6.5 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 Environment Variable Leak |
| CVE-2026-72783 | 6.2 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 Path Traversal via ensurePathIsContained |
| CVE-2026-72779 | 4.5 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.6 Arbitrary File Read via SplFileObject |
| CVE-2026-72785 | 4.3 MEDIUM | Craft CMS before 5.10.6 Authorization Bypass via structures/move-element |
No comments yet