Skip to content
Threat Feed

Vendor

Craft CMS

10 briefs RSS
critical threat

iCagenda Unrestricted File Upload Vulnerability Leading to RCE (CVE-2026-48939)

Attackers are actively exploiting CVE-2026-48939, an unrestricted file upload vulnerability in iCagenda, to upload malicious PHP code and achieve remote code execution on affected web servers.

exploited PoC iCagenda +19 web-application rce file-upload cve
1r 2t 5c 7i updated
high advisory

Craft CMS RCE via Missing cleanseConfig in FieldsController

An authenticated administrator in Craft CMS (versions 5.5.0 to 5.9.13) is vulnerable to Remote Code Execution (RCE) via a missing input sanitization vulnerability in the `actionRenderCardPreview()` method of `FieldsController`, allowing Yii2 event handler injection through specially crafted `fieldLayoutConfig` POST parameters, which enables arbitrary PHP code execution and sensitive information disclosure.

Craft CMS rce web-application cms craft-cms php
1r 1t
high advisory

Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget

An attacker with only a GitHub account can plant a malicious JavaScript payload in a GitHub issue title, leading to a DOM Cross-Site Scripting (XSS) vulnerability (CVE-2026-55790) that executes in a Craft CMS administrator's control panel session when they use the CraftSupport widget and retrieve the poisoned issue, allowing for arbitrary JavaScript execution and potential unauthorized actions.

Craft CMS 5.x +1 xss web-vulnerability craft-cms application-layer
1t 1c 1i
high advisory

Craft CMS Authorship Spoofing via Authorization Bypass (CVE-2026-50279)

A low-privileged authenticated user can exploit CVE-2026-50279, an authorization bypass vulnerability in Craft CMS's `entries/save-entry` endpoint, to reassign an entry's authorship to another user without proper permissions, leading to corrupted audit trails and misleading content ownership.

Craft CMS authorship-spoofing authorization-bypass web-application craft-cms cve
2t 1c
high advisory

Craft CMS Vulnerability Allows Low-Privilege Users to Delete Peer Assets

A low-privilege user with `deleteAssets` permission in Craft CMS can bypass the `deletePeerAssets` check in the `AssetsController::actionDeleteFolder` function, allowing them to delete assets uploaded by other users (peer assets) within a shared volume, despite lacking the specific `deletePeerAssets` permission, leading to unauthorized data destruction.

Craft CMS +1 craft-cms vulnerability privilege-escalation data-deletion web-application
1t 1c
high advisory

Craft CMS Mass Assignment Vulnerability Allows Element Overwrites (CVE-2026-50281)

A high-severity mass assignment vulnerability (CVE-2026-50281) in Craft CMS versions prior to 5.9.21 allows a low-privileged authenticated attacker to overwrite arbitrary existing element data, such as entries or user profiles, by manipulating the `newAttributes` parameter during a bulk duplication action.

Craft CMS web-application vulnerability mass-assignment cve cms
1t 1c
high advisory

Craft CMS Vulnerable to Unauthorized Folder Deletion (CVE-2026-50282)

A high-severity vulnerability (CVE-2026-50282) in Craft CMS allows an authenticated user to delete destination folders and their contents without explicit delete permissions during a forced folder move operation, enabling asset loss, breaking existing asset references, and causing operational disruption.

Craft CMS +1 authorization-bypass cms craft-cms webserver cve
1t 1c
high advisory

Craft CMS GraphQL Address Resolver Missing Authorization Allows PII Disclosure

A missing authorization check in the GraphQL Address element resolver of Craft CMS Pro allows a GraphQL API token scoped to a low-privilege user group to read all addresses in the system, including those belonging to users in groups the token is not authorized to access, exposing personally identifiable information (PII).

cms +2 craftcms graphql pii disclosure
2r 1t
high advisory

Craft Commerce Blind SQL Injection via hasVariant/hasProduct Properties

A blind SQL injection vulnerability exists in Craft Commerce's `ProductQuery::hasVariant` and `VariantQuery::hasProduct` properties, allowing authenticated control panel users to extract arbitrary database contents and potentially escalate privileges.

Craft Commerce sqli craft-commerce web-application
3r 1t 1c
high advisory

Craft CMS Authenticated Remote Code Execution via Malicious Attached Behavior

Craft CMS versions before 4.17.12 and 5.9.18 are vulnerable to authenticated remote code execution via malicious behavior injection in the field layout hydration path.

cms +1 craft-cms rce vulnerability
2r 2t