Craft CMS versions 4.x through 4.17.8 and 5.x through 5.9.14 are vulnerable to multiple security issues, including Server-Side Request Forgery and unauthenticated JavaScript resource proxying.
Claims
Craft CMS versions 4.x through 4.17.8 and 5.x through 5.9.14 are vulnerable to multiple security issues, including Server-Side Request Forgery and unauthenticated JavaScript resource proxying.
Parent: CybersecurityEntity: Craft CMSSub-entity: versions 4.x through 4.17.8 and 5.x through 5.9.14Impact: negativeDate: Apr 22, 2026Target: Craft CMS security vulnerabilities
Source posts
๐จ EUVD-2026-24569
๐ Score: 5.5/10 (CVSS v3.1)
๐ฆ Product: CMS, CMS
๐ข Vendor: craftcms
๐
Updated: 2026-04-21
๐ Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema:...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24569
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24567
๐ Score: 5.3/10 (CVSS v3.1)
๐ฆ Product: CMS
๐ข Vendor: craftcms
๐
Updated: 2026-04-21
๐ Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group ...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24567
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
๐จ EUVD-2026-24571
๐ Score: 5.5/10 (CVSS v3.1)
๐ฆ Product: CMS, CMS
๐ข Vendor: craftcms
๐
Updated: 2026-04-21
๐ Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources.
When `trustedHost...
๐ https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24571
#cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability