Craft CMS 5.0.0 至 5.10.12 版本将数据库连接失败视为“Craft 未安装”,导致在已安装的生产站点上,当 PHP 服务正常但配置的 MySQL 端点不可用时,匿名的安装器操作(包括 install 和 validate-site)变得可访问。该操作接受一个站点名称,通过 进行序列化,并使用 展开 表达式。若未认证攻击者在故障发生前已获取访客会话 Cookie 及匹配的 CSRF 令牌,且该会话在故障期间仍然有效,则攻击者可提交一个可预测的变量名(例如 Craft 约定的 ),从而获取其值,进
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92592 | 8.8 HIGH | Craft CMS before 4.18.6 Remote Code Execution via signed cookie |
| CVE-2026-92593 | 8.8 HIGH | Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution |
| CVE-2026-92594 | 7.5 HIGH | Craft CMS before 5.11.0 Unauthenticated PII Disclosure via GraphQL |
| CVE-2026-92590 | 5.4 MEDIUM | Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields |
| CVE-2026-92589 | 4.3 MEDIUM | Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder |
No comments yet