โ† All reports

Craft CMS versions 4.x through 4.17.8 and 5.x through 5.9.14 are vulnerable to multiple security issues, including Server-Side Request Forgery and unauthenticated JavaScript resource proxying.

CybersecurityTechnologyConflictContent Management SystemsApr 22, 2026score 0.173 posts ยท 0 replies across 1 instances
This thread discusses multiple security vulnerabilities in Craft CMS, including Server-Side Request Forgery, unauthenticated JavaScript resource proxying, and user group manipulation. These issues affect specific versions of the CMS and highlight potential risks to system security.

Claims

Craft CMS versions 4.x through 4.17.8 and 5.x through 5.9.14 are vulnerable to multiple security issues, including Server-Side Request Forgery and unauthenticated JavaScript resource proxying.
Parent: CybersecurityEntity: Craft CMSSub-entity: versions 4.x through 4.17.8 and 5.x through 5.9.14Impact: negativeDate: Apr 22, 2026Target: Craft CMS security vulnerabilities

Source posts

@[email protected]
๐Ÿšจ EUVD-2026-24569 ๐Ÿ“Š Score: 5.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: CMS, CMS ๐Ÿข Vendor: craftcms ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema:... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24569 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24567 ๐Ÿ“Š Score: 5.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: CMS ๐Ÿข Vendor: craftcms ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group ... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24567 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
๐Ÿšจ EUVD-2026-24571 ๐Ÿ“Š Score: 5.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: CMS, CMS ๐Ÿข Vendor: craftcms ๐Ÿ“… Updated: 2026-04-21 ๐Ÿ“ Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources. When `trustedHost... ๐Ÿ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24571 #cybersecurity #infosec #euvd #cve #vulnerability
1 boosts ยท 0 favs ยท 0 replies ยท Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability