craftcms/cms Security Advisories for 4.16.17 (11)
-
[LOW] Craft CMS has Stored XSS in Table Field in its "Row Heading" Column Type
PKSA-cf9h-wtzj-5nwd GHSA-6j87-m5qx-9fqp
Affected version: >=5.0.0-RC1,<=5.8.22|>=4.5.0-beta.1,<=4.16.18
Reported by:
GitHub -
[MEDIUM] Craft CMS: Cloud Metadata SSRF Protection Bypass via IPv6 Resolution
PKSA-qgft-95tr-t5vt CVE-2026-27129 GHSA-v2gc-rm6g-wrw9
Affected version: >=3.5.0,<=4.16.18|>=5.0.0-RC1,<=5.8.22
Reported by:
GitHub -
[MEDIUM] Craft CMS Race condition in Token Service potentially allows for token usage greater than the token limit
PKSA-k33k-b5qw-yqgp CVE-2026-27128 GHSA-6fx5-5cw5-4897
Affected version: >=5.0.0-RC1,<=5.8.22|>=4.5.0-RC1,<=4.16.18
Reported by:
GitHub -
[HIGH] Craft CMS has Cloud Metadata SSRF Protection Bypass via DNS Rebinding
PKSA-ycmx-j7s8-wyxz CVE-2026-27127 GHSA-gp2f-7wcm-5fhx
Affected version: >=3.5.0,<=4.16.18|>=5.0.0-RC1,<=5.8.22
Reported by:
GitHub -
[MEDIUM] Craft CMS has Stored XSS in Table Field via "HTML" Column Type
PKSA-knkq-h2rk-yc48 CVE-2026-27126 GHSA-3jh3-prx3-w6wc
Affected version: >=5.0.0-RC1,<=5.8.22|>=4.5.0-RC1,<=4.16.18
Reported by:
GitHub -
[HIGH] Craft CMS Vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
PKSA-g2n6-j3mn-x8xf CVE-2026-25498 GHSA-7jx7-3846-m7w7
Affected version: >=4.0.0-RC1,<=4.16.17|>=5.0.0-RC1,<=5.8.21
Reported by:
GitHub -
[HIGH] Craft CMS: GraphQL Asset Mutation Privilege Escalation
PKSA-zjy6-pdtw-mck8 CVE-2026-25497 GHSA-fxp3-g6gw-4r4v
Affected version: >=4.0.0-RC1,<4.17.0-beta.1|>=5.0.0-RC1,<5.9.0-beta.1
Reported by:
GitHub -
[MEDIUM] Craft CMS Vulnerable to Stored XSS in Number Prefix & Suffix Fields
PKSA-5pj5-nxp6-547h CVE-2026-25496 GHSA-9f5h-mmq6-2x78
Affected version: >=4.0.0-RC1,<=4.16.17|>=5.0.0-RC1,<=5.8.21
Reported by:
GitHub -
[HIGH] Craft CMS Vulnerable to SQL Injection in Element Indexes via `criteria[orderBy]`
PKSA-9dtd-sv51-7pmx CVE-2026-25495 GHSA-2453-mppf-46cj
Affected version: >=4.0.0-RC1,<=4.16.17|>=5.0.0-RC1,<=5.8.21
Reported by:
GitHub -
[MEDIUM] Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via Alternative IP Notation
PKSA-jsy4-k6z3-fcjb CVE-2026-25494 GHSA-m5r2-8p9x-hp5m
Affected version: >=4.0.0-RC1,<=4.16.17|>=5.0.0-RC1,<=5.8.21
Reported by:
GitHub -
[MEDIUM] Craft CMS Vulnerable to SSRF in GraphQL Asset Mutation via HTTP Redirect
PKSA-1dbt-xzgs-7gw8 CVE-2026-25493 GHSA-8jr8-7hr4-vhfx
Affected version: >=4.0.0-RC1,<=4.16.17|>=5.0.0-RC1,<=5.8.21
Reported by:
GitHub