Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) opens another author's
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92592 | 8.8 HIGH | Craft CMS before 4.18.6 Remote Code Execution via signed cookie |
| CVE-2026-92593 | 8.8 HIGH | Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution |
| CVE-2026-92594 | 7.5 HIGH | Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL |
| CVE-2026-92591 | 5.9 MEDIUM | Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer |
| CVE-2026-92590 | 5.4 MEDIUM | Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields |
No comments yet