Craft CMS是Craft CMS公司的一套内容管理系统(CMS)。 Craft CMS 5.10.12之前版本存在代码注入漏洞,该漏洞源于对字符串类型字段布局元素清理不当,经过身份验证的控制面板用户可通过发布JSON字符串形式的字段布局选项卡元素绕过清理验证,注入Yii2行为附件和事件处理程序,从而触发任意对象实例化和代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86732 | 8.8 HIGH | Craft CMS before 5.10.12 Remote Code Execution via element-index |
| CVE-2026-86731 | 6.5 MEDIUM | Craft CMS 5.0.0-RC1 before 5.10.12 Permission Escalation via UsersController |
No comments yet