在 Craft CMS 5.10.11 之前的版本中,系统在用户注册过程中未能正确验证“管理员”标志(admin flag),导致该标志可以从已停用的管理员账户中延续下来。攻击者可以利用已停用的管理员的邮箱地址进行注册,从而在启用公开注册且禁用邮箱验证的配置下继承管理员权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84801 | 8.8 HIGH | Craft CMS 5.0.0-RC1 before 5.10.11 Authentication Bypass via administrateUsers |
| CVE-2026-84796 | 8.8 HIGH | Craft CMS 5.0.0-RC1 before 5.10.11 GraphQL Entry Mutation Site Scope Bypass |
| CVE-2026-84794 | 7.1 HIGH | Craft CMS 5.0.0 through 5.10.10 Authorization Bypass via assets/move-asset |
| CVE-2026-84800 | 7.1 HIGH | Craft CMS 5.0.0-RC1 before 5.10.11 File Overwrite via assets/replace-file |
| CVE-2026-84798 | 7.1 HIGH | Craft CMS before 5.10.11 Authorization Bypass via actionDeleteForSite |
| CVE-2026-84797 | 6.3 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.11 Authorization Bypass via actionDuplicate |
| CVE-2026-84793 | 4.8 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.11 Stored XSS via site name |
| CVE-2026-84792 | 4.3 MEDIUM | Craft CMS before 5.10.11 Broken Access Control via element-indexes |
| CVE-2026-84802 | 4.3 MEDIUM | Craft CMS 5.7.0 before 5.10.12 Information Disclosure via AssetsController |
| CVE-2026-84799 | 4.3 MEDIUM | Craft CMS before 5.11.0 PII Disclosure via GraphQL User Relations |
No comments yet