Security: craftcms/cms
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Missing Authorization Check on User Group Removal via save-permissions ActionGHSA-jq2f-59pj-p3m3 published
Apr 13, 2026 by angrybradModerate -
Server-Side Request Forgery (SSRF) in Craft CMS with Asset Uploads MutationsGHSA-3m9m-24vh-39wx published
Apr 13, 2026 by angrybradModerate -
Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section permissionsGHSA-f582-6gf6-gx4g published
Mar 24, 2026 by angrybradModerate -
Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permissionGHSA-x76w-8c62-48mg published
Jun 2, 2026 by angrybradLow -
Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized usersGHSA-vgjg-248p-rfm2 published
Mar 24, 2026 by angrybradLow -
Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadataGHSA-44px-qjjc-xrhq published
Mar 24, 2026 by angrybradLow -
Anonymous "generate transform" calls for assets can expose private assets via transform URLGHSA-5pgf-h923-m958 published
Mar 24, 2026 by angrybradModerate -
Low-privilege users could read private asset contents when editing an asset (IDOR)GHSA-3pvf-vxrv-hh9c published
Mar 24, 2026 by angrybradModerate -
RCE via missing cleanseConfig in FieldsController::actionRenderCardPreviewGHSA-86vw-x4ww-x467 published
Jun 2, 2026 by angrybradModerate -
Unauthenticated users could execute project configuration sync operations that should be restricted trusted usersGHSA-6mrr-q3pj-h53w published
Mar 24, 2026 by angrybradModerate