Security: craftcms/cms
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Stored XSS in breadcrumb list and title fieldsGHSA-28h4-788g-rh42 published
Sep 9, 2024 by angrybradModerate -
Privilege EscalationGHSA-j5g9-j7r4-6qvx published
Jan 3, 2024 by angrybradModerate -
Remote Code ExecutionGHSA-4w8r-3xrw-v25g published
Sep 13, 2023 by angrybradCritical -
Remote Code Execution via validatePath bypassGHSA-44wr-rmwq-3phw published
Aug 19, 2023 by angrybradModerate -
Stored XSS in review volumneGHSA-cjmm-x9x9-m2w5 published
May 25, 2023 by angrybradModerate -
XSS in RSS feed widgetGHSA-j4mx-98hw-6rv6 published
May 5, 2023 by angrybradModerate -
Stored XSS in indexedVolumesGHSA-6qjx-787v-6pxr published
May 25, 2023 by angrybradModerate -
XSS in RSS widget feedGHSA-qpgm-gjgf-8c2x published
May 25, 2023 by angrybradModerate -
Stored XSS in Quick Post widget error messageGHSA-3wxg-w96j-8hq9 published
May 25, 2023 by angrybradLow -
Remote Code Execution via unrestricted file extensionGHSA-vqxf-r9ph-cc9c published
May 19, 2023 by angrybradHigh