craftcms/cms Security Advisories for 5.10.6 (3)
-
[MEDIUM] Craft CMS: Stored XSS in the control panel via unescaped draft name
PKSA-x767-zzvx-956t GHSA-2rp4-x2j7-qmcc
Affected version: >=5.0.0-RC1,<5.10.8
Reported by:
GitHub -
[HIGH] Craft CMS: Arbitrary user password reset leading to administrator account takeover
PKSA-s5dz-k87m-97ms GHSA-p8x7-9vfw-p7vc
Affected version: >=5.0.0-RC1,<5.10.8
Reported by:
GitHub -
[HIGH] Craft CMS: Authenticated RCE through Twig sandbox escape
PKSA-d48x-nyby-nphv GHSA-f5wm-88jv-g5hx
Affected version: >=4.0.0-RC1,<4.18.3|>=5.0.0-RC1,<5.10.7
Reported by:
GitHub