craftcms/cms Security Advisories for 5.6.10.2 (22)
-
[LOW] Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type
PKSA-cf9h-wtzj-5nwd GHSA-6j87-m5qx-9fqp
Affected version: >=5.0.0-RC1,<=5.8.22|>=4.5.0-beta.1,<=4.16.18
Reported by:
GitHub -
[MEDIUM] Craft CMS: Cloud Metadata SSRF Protection Bypass via IPv6 Resolution
PKSA-qgft-95tr-t5vt CVE-2026-27129 GHSA-v2gc-rm6g-wrw9
Affected version: >=3.5.0,<=4.16.18|>=5.0.0-RC1,<=5.8.22
Reported by:
GitHub -
[MEDIUM] Craft CMS Race condition in Token Service potentially allows for token usage greater than the token limit
PKSA-k33k-b5qw-yqgp CVE-2026-27128 GHSA-6fx5-5cw5-4897
Affected version: >=5.0.0-RC1,<=5.8.22|>=4.5.0-RC1,<=4.16.18
Reported by:
GitHub -
[HIGH] Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding
PKSA-ycmx-j7s8-wyxz CVE-2026-27127 GHSA-gp2f-7wcm-5fhx
Affected version: >=3.5.0,<=4.16.18|>=5.0.0-RC1,<=5.8.22
Reported by:
GitHub -
[MEDIUM] Craft CMS has Stored XSS in Table Field via "HTML" Column Type
PKSA-knkq-h2rk-yc48 CVE-2026-27126 GHSA-3jh3-prx3-w6wc
Affected version: >=5.0.0-RC1,<=5.8.22|>=4.5.0-RC1,<=4.16.18
Reported by:
GitHub -
[HIGH] Craft CMS Vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
PKSA-g2n6-j3mn-x8xf CVE-2026-25498 GHSA-7jx7-3846-m7w7
Affected version: >=4.0.0-RC1,<=4.16.17|>=5.0.0-RC1,<=5.8.21
Reported by:
GitHub -
[HIGH] Craft CMS: GraphQL Asset Mutation Privilege Escalation
PKSA-zjy6-pdtw-mck8 CVE-2026-25497 GHSA-fxp3-g6gw-4r4v
Affected version: >=4.0.0-RC1,<4.17.0-beta.1|>=5.0.0-RC1,<5.9.0-beta.1
Reported by:
GitHub -
[MEDIUM] Craft CMS Vulnerable to Stored XSS in Number Prefix & Suffix Fields
PKSA-5pj5-nxp6-547h CVE-2026-25496 GHSA-9f5h-mmq6-2x78
Affected version: >=4.0.0-RC1,<=4.16.17|>=5.0.0-RC1,<=5.8.21
Reported by:
GitHub -
[HIGH] Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`
PKSA-9dtd-sv51-7pmx CVE-2026-25495 GHSA-2453-mppf-46cj
Affected version: >=4.0.0-RC1,<=4.16.17|>=5.0.0-RC1,<=5.8.21
Reported by:
GitHub -
[MEDIUM] Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via Alternative IP Notation
PKSA-jsy4-k6z3-fcjb CVE-2026-25494 GHSA-m5r2-8p9x-hp5m
Affected version: >=4.0.0-RC1,<=4.16.17|>=5.0.0-RC1,<=5.8.21
Reported by:
GitHub -
[MEDIUM] Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via HTTP Redirect
PKSA-1dbt-xzgs-7gw8 CVE-2026-25493 GHSA-8jr8-7hr4-vhfx
Affected version: >=4.0.0-RC1,<=4.16.17|>=5.0.0-RC1,<=5.8.21
Reported by:
GitHub -
[LOW] Craft CMS Vulnerable to Stored XSS in Entry Types Name
PKSA-v2dw-c4ss-13bw CVE-2026-25491 GHSA-7pr4-wx9w-mqwr
Affected version: >=5.0.0-RC1,<=5.8.21
Reported by:
GitHub -
[HIGH] Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
PKSA-hcvs-d728-5zyw CVE-2025-68455 GHSA-255j-qw47-wjh5
Affected version: >=4.0.0-RC1,<=4.16.16|>=5.0.0-RC1,<=5.8.20
Reported by:
GitHub -
[HIGH] Unauthenticated Craft CMS users can trigger a database backup
PKSA-17hr-tk5g-ht8k CVE-2025-68456 GHSA-v64r-7wg9-23pr
Affected version: >=3.0.0,<=4.16.16|>=5.0.0-RC1,<=5.8.20
Reported by:
GitHub -
[MEDIUM] Craft CMS vulnerable to potential authenticated Remote Code Execution via Twig SSTI
PKSA-9rbz-gy92-qjtd CVE-2025-68454 GHSA-742x-x762-7383
Affected version: >=4.0.0-RC1,<=4.16.16|>=5.0.0-RC1,<=5.8.20
Reported by:
GitHub -
[MEDIUM] Craft CMS vulnerable to Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation
PKSA-4gr3-459g-ssmq CVE-2025-68437 GHSA-x27p-wfqw-hfcc
Affected version: >=3.5.0,<=4.16.16|>=5.0.0-RC1,<=5.8.20
Reported by:
GitHub -
[MEDIUM] Craft CMS vulnerable to potential information disclosure via unchecked asset relocation
PKSA-yj3g-znh5-93sd CVE-2025-68436 GHSA-53vf-c43h-j2x9
Affected version: >=4.0.0-RC1,<=4.16.16|>=5.0.0-RC1,<=5.8.20
Reported by:
GitHub -
[MEDIUM] Craft CMS Potential Remote Code Execution via Twig SSTI
PKSA-cbq7-fhfn-fyt5 CVE-2025-57811 GHSA-crcq-738g-pqvc
Affected version: >=5.0.0-RC1,<=5.8.6|>=4.0.0-RC1,<=4.16.5
Reported by:
GitHub -
[MEDIUM] Craft CMS has a theoretical bypass for CVE-2025-23209
PKSA-xnt5-5jkh-xr5x CVE-2025-54417 GHSA-2vcf-qxv3-2mgw
Affected version: >=5.5.8,<5.8.4|>=4.13.8,<4.16.3
Reported by:
GitHub -
[MEDIUM] Craft CMS stores arbitrary content provided by unauthenticated users in session files
PKSA-ht16-h36v-hxc7 CVE-2025-35939 GHSA-7vrx-9684-xrf2
Affected version: <4.15.3|>=5.0.0-alpha.1,<5.7.5
Reported by:
GitHub -
[HIGH] Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI
PKSA-8gxy-mg5h-z15w CVE-2025-46731 GHSA-7c58-g782-9j38
Affected version: >=5.0.0-RC1,<=5.6.14|>=4.0.0-RC1,<=4.14.12
Reported by:
GitHub -
[CRITICAL] Craft CMS Allows Remote Code Execution
PKSA-5c44-5nbz-c7cq CVE-2025-32432 GHSA-f3gw-9ww9-jmc3
Affected version: >=5.0.0-RC1,<=5.6.16|>=4.0.0-RC1,<=4.14.14|>=3.0.0-RC1,<=3.9.14
Reported by:
GitHub