Known Vulnerabilities for Craft Cms by Craftcms
Listed below are 10 of the newest known vulnerabilities associated with "Craft Cms" by "Craftcms".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-90472 json | msgpack-java through 0.9.12 contains a stack overflow vulnerability in MessageUnpacker.unpackValue() that recursively deseria... | Not Provided | 2026-09-12 | 2026-09-12 |
| CVE-2026-90467 json | aiosmtplib before 5.1.3 fails to properly validate email addresses supplied by callers, allowing attackers to inject ESMTP pa... | Not Provided | 2026-09-12 | 2026-09-12 |
| CVE-2026-90453 json | A file-upload handler redirects the authenticated client's browser to a URL taken directly from that same request's Referer h... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-90445 json | An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-90443 json | A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encodi... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-89266 json | stb_vorbis through 1.22 contains a heap buffer overflow in start_decoder() where the codebook multiplicands allocation size i... | Not Provided | 2026-09-12 | 2026-09-11 |
| CVE-2026-89247 json | WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-89245 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in pl... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-89241 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability i... | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-89240 json | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability i... | Not Provided | 2026-09-11 | 2026-09-11 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Craftcms | Craft Cms | 3.4.9 | |||
| Application | Craftcms | Craft Cms | 3.4.8 | |||
| Application | Craftcms | Craft Cms | 3.4.7.1 | |||
| Application | Craftcms | Craft Cms | 3.4.7 | |||
| Application | Craftcms | Craft Cms | 3.4.6.1 | |||
| Application | Craftcms | Craft Cms | 3.4.6 | |||
| Application | Craftcms | Craft Cms | 3.4.5 | |||
| Application | Craftcms | Craft Cms | 3.4.4.1 | |||
| Application | Craftcms | Craft Cms | 3.4.4 | |||
| Application | Craftcms | Craft Cms | 3.4.3 | |||
| Application | Craftcms | Craft Cms | 3.4.25 | |||
| Application | Craftcms | Craft Cms | 3.4.24 | |||
| Application | Craftcms | Craft Cms | 3.4.23 | |||
| Application | Craftcms | Craft Cms | 3.4.22.1 | |||
| Application | Craftcms | Craft Cms | 3.4.22 | |||
| Application | Craftcms | Craft Cms | 3.4.21 | |||
| Application | Craftcms | Craft Cms | 3.4.20 | |||
| Application | Craftcms | Craft Cms | 3.4.2 | |||
| Application | Craftcms | Craft Cms | 3.4.19.1 | |||
| Application | Craftcms | Craft Cms | 3.4.19 |