Craft CMS 在 5.11.0 之前的版本未能对原生 GraphQL 用户关联(包括 author、authors、uploader、draftCreator 和 revisionCreator 字段)强制应用用户组作用域过滤器。拥有受限 GraphQL 令牌的攻击者可以查询这些关联,从而读取任意内容作者或上传者(包括管理员)的用户名、电子邮件地址和全名。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-84795 | 9.8 CRITICAL | Craft CMS before 5.10.11 Authentication Bypass via Admin Flag Inheritance |
| CVE-2026-84801 | 8.8 HIGH | Craft CMS 5.0.0-RC1 before 5.10.11 Authentication Bypass via administrateUsers |
| CVE-2026-84796 | 8.8 HIGH | Craft CMS 5.0.0-RC1 before 5.10.11 GraphQL Entry Mutation Site Scope Bypass |
| CVE-2026-84794 | 7.1 HIGH | Craft CMS 5.0.0 through 5.10.10 Authorization Bypass via assets/move-asset |
| CVE-2026-84800 | 7.1 HIGH | Craft CMS 5.0.0-RC1 before 5.10.11 File Overwrite via assets/replace-file |
| CVE-2026-84798 | 7.1 HIGH | Craft CMS before 5.10.11 Authorization Bypass via actionDeleteForSite |
| CVE-2026-84797 | 6.3 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.11 Authorization Bypass via actionDuplicate |
| CVE-2026-84793 | 4.8 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.11 Stored XSS via site name |
| CVE-2026-84792 | 4.3 MEDIUM | Craft CMS before 5.10.11 Broken Access Control via element-indexes |
| CVE-2026-84802 | 4.3 MEDIUM | Craft CMS 5.7.0 before 5.10.12 Information Disclosure via AssetsController |
No comments yet