Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are gated only on the elem
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92592 | 8.8 HIGH | Craft CMS before 4.18.6 Remote Code Execution via signed cookie |
| CVE-2026-92593 | 8.8 HIGH | Craft CMS 5.10.0 before 5.10.13 Authenticated Remote Code Execution |
| CVE-2026-92591 | 5.9 MEDIUM | Craft CMS 5.0.0 before 5.10.13 Environment Secret Exposure via Installer |
| CVE-2026-92590 | 5.4 MEDIUM | Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields |
| CVE-2026-92589 | 4.3 MEDIUM | Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder |
No comments yet