craftcms/cms Security Advisories for 4.18.1 (5)
-
[MEDIUM] Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
PKSA-19kf-75v5-vy76 GHSA-957r-qf9p-67xw
Affected version: >=4.0.0-RC1,<4.18.2|>=5.0.0-RC1,<5.10.6
Reported by:
GitHub -
[MEDIUM] Craft CMS: Authenticated leak of secret environment variables
PKSA-4q3g-gxhk-813s GHSA-596p-6jv8-775v
Affected version: >=4.0.0-RC1,<4.18.2|>=5.0.0-RC1,<5.10.6
Reported by:
GitHub -
[LOW] Craft CMS: Incorrect path validation could potentially lead to path traversal
PKSA-82nd-44zr-vpmz GHSA-7hxc-f267-h5q7
Affected version: >=4.0.0-RC1,<4.18.2|>=5.0.0-RC1,<5.10.6
Reported by:
GitHub -
[HIGH] Craft CMS: Authenticated RCE through Twig sandbox escape
PKSA-d48x-nyby-nphv GHSA-f5wm-88jv-g5hx
Affected version: >=4.0.0-RC1,<4.18.3|>=5.0.0-RC1,<5.10.7
Reported by:
GitHub -
[HIGH] Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
PKSA-4tjq-33kk-ghq8 GHSA-265m-7826-wjqm
Affected version: >=4.0.0-RC1,<4.18.2|>=5.0.0-RC1,<5.10.6
Reported by:
GitHub