Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Crafter CMS — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in Crafter CMS, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of Common Weakness Enumerations (CWE) affecting the content management system product, Crafter CMS. It serves as a centralized resource for security professionals and administrators seeking detailed insights into the specific vulnerabilities associated with this software platform. The content gathered here encompasses a wide range of security flaws, including but not limited to cross-site scripting, privilege escalation, and insecure direct object references, which have been documented and reported for Crafter CMS over the past decade. By compiling data from multiple authoritative sources, this repository ensures a holistic view of the threat landscape, covering incidents from early releases to the most recent updates. Users visiting this page can effectively track vendor advisories and security bulletins issued by Crafter CMS, allowing them to stay informed about newly disclosed risks and patch availability. Furthermore, it offers a deeper understanding of specific weakness classes by illustrating how common vulnerability patterns manifest within this particular technology stack. Administrators can also look up the complete vulnerability history of Crafter CMS to assess past security incidents and evaluate the overall maturity of its security response mechanisms. This historical perspective aids in making informed decisions regarding system upgrades, mitigation strategies, and long-term risk management. The aggregated data is presented in a structured format to facilitate easy searching and analysis, ensuring that security teams can quickly identify relevant information without sifting through disparate sources. This approach supports proactive security posture maintenance and helps organizations prioritize remediation efforts based on verified and contextualized data points related to Crafter CMS.

Vendor: Crafter Software

CVE IDTitleCVSSSeverityPublished
CVE-2022-40635 Improper Control of Dynamically-Managed Code Resources in Crafter Studio CWE-913 6.4 Medium2022-09-13
CVE-2022-40634 Improper Control of Dynamically-Managed Code Resources in Crafter Studio CWE-913 6.4 Medium2022-09-13
CVE-2021-23267 Improper Control of Dynamically-Managed Code Resources in Crafter Studio CWE-913 7.6 High2022-05-16
CVE-2021-23266 Improper Output Neutralization for Logs in Crafter Studio CWE-117 4.3 Medium2022-05-16
CVE-2021-23265 Improper Privilege Management in Crafter Studio CWE-269 3.5 Low2022-05-16
CVE-2021-23264 Transmission of Private Resources into a New Sphere ('Resource Leak') and Exposure of Resource to Wrong Sphere in Crafter Search CWE-402 8.1 High2021-12-02
CVE-2021-23262 Snakeyaml deserialization vulnerability bypass CWE-913 4.2 Medium2021-12-02
CVE-2021-23263 Transmission of Private Resources into a New Sphere ('Resource Leak') in Crafter Engine CWE-402 5.9 Medium2021-12-02
CVE-2021-23261 Overriding the system configuration file causes a denial of service CWE-703 4.5 Medium2021-12-02
CVE-2021-23259 Groovy Sandbox Bypass CWE-913 4.2 Medium2021-12-02
CVE-2021-23260 Stored XSS Vulnerability in File Name of the File Upload function CWE-79 6.5 Medium2021-12-02
CVE-2021-23258 Spring SPEL Expression Language Injection CWE-913 4.2 Medium2021-12-02
CVE-2020-25803 Authenticated attackers with developer privileges in Crafter Studio may execute OS commands via deep inspection of FreeMarker template exposed objects. CWE-913 4.2 Medium2020-10-06
CVE-2020-25802 Authenticated attackers with developer privileges in Crafter Studio may execute OS commands via Groovy scripting. CWE-913 4.2 Medium2020-10-06

All 14 known CVE vulnerabilities affecting Crafter CMS with full Chinese analysis, references, and POCs where available.