craftcms/cms Security Advisories for 5.9.13 (35)
-
[CRITICAL] Craft CMS: Passkey login accepts replayed WebAuthn assertions
PKSA-jk69-ryht-534b GHSA-wg23-69c2-gjc8
Affected version: >=5.0.0-RC1,<5.10.5
Reported by:
GitHub -
[MEDIUM] Craft CMS: Arbitrary file read via SplFileObject in non-sandboxed template contexts
PKSA-19kf-75v5-vy76 GHSA-957r-qf9p-67xw
Affected version: >=4.0.0-RC1,<4.18.2|>=5.0.0-RC1,<5.10.6
Reported by:
GitHub -
[MEDIUM] Craft CMS: Authenticated leak of secret environment variables
PKSA-4q3g-gxhk-813s GHSA-596p-6jv8-775v
Affected version: >=4.0.0-RC1,<4.18.2|>=5.0.0-RC1,<5.10.6
Reported by:
GitHub -
[MEDIUM] Craft CMS: Missing authorization check allows non-admin control panel users access to user registration metrics
PKSA-1412-5vdy-cd6w GHSA-rvmm-v933-jgxq
Affected version: >=5.0.0-RC1,<5.10.3|>=4.0.0-RC1,<4.18.1
Reported by:
GitHub -
[LOW] Craft CMS: Incorrect path validation could potentially lead to path traversal
PKSA-82nd-44zr-vpmz GHSA-7hxc-f267-h5q7
Affected version: >=4.0.0-RC1,<4.18.2|>=5.0.0-RC1,<5.10.6
Reported by:
GitHub -
[MEDIUM] Craft CMS: Stored XSS in the control panel via unescaped draft name
PKSA-x767-zzvx-956t GHSA-2rp4-x2j7-qmcc
Affected version: >=5.0.0-RC1,<5.10.8
Reported by:
GitHub -
[HIGH] Craft CMS: Arbitrary user password reset leading to administrator account takeover
PKSA-s5dz-k87m-97ms GHSA-p8x7-9vfw-p7vc
Affected version: >=5.0.0-RC1,<5.10.8
Reported by:
GitHub -
[HIGH] Craft CMS: Authenticated RCE through Twig sandbox escape
PKSA-d48x-nyby-nphv GHSA-f5wm-88jv-g5hx
Affected version: >=4.0.0-RC1,<4.18.3|>=5.0.0-RC1,<5.10.7
Reported by:
GitHub -
[MEDIUM] Craft CMS: Missing authorization check allows non-admin control panel users to reorder Global Sets
PKSA-x2qp-qkxh-fw67 CVE-2026-14793 GHSA-9p7c-v5x3-rfx8
Affected version: >=5.0.0-RC1,<5.10.3|>=4.0.0-RC1,<4.18.1
Reported by:
GitHub -
[HIGH] Craft CMS: Authenticated RCE via `condition.config` JSON cleanse bypass
PKSA-4tjq-33kk-ghq8 GHSA-265m-7826-wjqm
Affected version: >=4.0.0-RC1,<4.18.2|>=5.0.0-RC1,<5.10.6
Reported by:
GitHub -
[HIGH] Craft CMS: RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview
PKSA-r87g-h2pd-9vq1 CVE-2026-56382 GHSA-86vw-x4ww-x467
Affected version: >=5.5.0,<=5.9.13
Reported by:
GitHub -
[HIGH] Craft CMS: Potential authenticated Remote Code Execution via referrer redirect
PKSA-hvdm-8k9p-kcdw CVE-2026-55794 GHSA-f74w-488g-8x5r
Affected version: >=5.9.0,<5.10.0
Reported by:
GitHub -
[MEDIUM] Craft CMS: Stored XSS via Structure entry title in table view
PKSA-z4vj-1h29-pkrc CVE-2026-55793 GHSA-xrqc-p465-2xvg
Affected version: >=5.0.0-RC1,<5.9.22
Reported by:
GitHub -
[MEDIUM] Craft CMS: Sensitive File Disclosure / Server-Side File Read
PKSA-rvh7-y4k6-cn59 CVE-2026-55792 GHSA-287w-mxq6-x2cp
Affected version: >=5.0.0-RC1,<5.10.0|>=4.0.0-RC1,<4.18.0
Reported by:
GitHub -
[HIGH] Craft CMS: DOM XSS via GitHub issue title in CraftSupport widget
PKSA-hm4p-n9yk-nz2c CVE-2026-55790 GHSA-24x4-j6x9-rfw5
Affected version: >=4.0.0-RC1,<4.17.15|>=5.0.0-RC1,<5.9.22
Reported by:
GitHub -
[MEDIUM] Craft CMS: Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission
PKSA-pqnm-5q4k-cx7j CVE-2026-56384 GHSA-x76w-8c62-48mg
Affected version: >=5.0.0-RC1,<=5.9.13|>=4.0.0-RC1,<=4.17.7
Reported by:
GitHub -
[HIGH] Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
PKSA-9z7r-2kcf-76cf CVE-2026-50282 GHSA-3w32-23wj-rxg3
Affected version: >=4.0.0-RC1,<4.17.14|>=5.0.0-RC1,<5.9.21
Reported by:
GitHub -
[HIGH] Craft CMS's mass assignment via id in newAttributes during bulk duplicate overwrites existing elements
PKSA-zn8p-45f7-kgv1 CVE-2026-50281 GHSA-x5m4-g2cq-52pq
Affected version: >=5.7.0,<5.9.21
Reported by:
GitHub -
[HIGH] Craft CMS: Missing peer-permission check in `AssetsController::actionDeleteFolder` allows deletion of other users' assets
PKSA-fd42-dyd4-g3dq CVE-2026-50284 GHSA-7h62-6v23-v8fm
Affected version: >=4.0.0-RC1,<4.17.15|>=5.0.0-RC1,<5.9.22
Reported by:
GitHub -
[MEDIUM] Craft CMS: Unauthorized Deletion of Source Assets During File Replacement
PKSA-68rr-18x7-w4gg CVE-2026-50283 GHSA-qh45-9g5p-m2v4
Affected version: >=4.0.0-RC1,<4.17.14|>=5.0.0-RC1,<5.9.21
Reported by:
GitHub -
[MEDIUM] Craft CMS: Authorization bypass in `entries/move-to-section` via missing target-section save check
PKSA-nhns-q2yx-ct2v CVE-2026-50280 GHSA-43cq-c2gq-pfpw
Affected version: >=5.0.0-RC1,<5.9.21
Reported by:
GitHub -
[HIGH] Craft CMS: Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap
PKSA-rg3c-2r2k-sf93 CVE-2026-50279 GHSA-qq2c-2q8j-jh27
Affected version: >=5.0.0-RC1,<5.9.21
Reported by:
GitHub -
[CRITICAL] Craft CMS: Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs
PKSA-5xds-5mf3-ckxn CVE-2026-55791 GHSA-c55v-343g-5xff
Affected version: >=4.0.0-RC1,<4.18|>=5.0.0-RC1,<5.10
Reported by:
GitHub -
[HIGH] Craft CMS's Missing Volume Permission Check in AssetsController::actionShowInFolder Allows Information Disclosure
PKSA-tj2m-c963-6jtt CVE-2026-44012 GHSA-33m5-hqp9-97pw
Affected version: >=5.0.0-RC1,<5.9.18
Reported by:
GitHub -
[HIGH] Craft CMS has Potential Authenticated Remote Code Execution via Malicious Attached Behavior
PKSA-7b21-z11x-97gc CVE-2026-44011 GHSA-qrgm-p9w5-rrfw
Affected version: >=5.0.0,<5.9.18|>=4.0.0,<4.17.12
Reported by:
GitHub -
[HIGH] Craft CMS's Missing Authorization in GraphQL Address Resolver Allows Cross-Scope PII Disclosure
PKSA-sxz1-z4jg-2vhh CVE-2026-44010 GHSA-gj2p-p9m4-c8gw
Affected version: >=4.0.0,<4.17.12|>=5.0.0,<5.9.18
Reported by:
GitHub -
[MEDIUM] Craft CMS has a host header injection leading to SSRF via resource-js endpoint
PKSA-ntd3-69q5-4cfy CVE-2026-41130 GHSA-95wr-3f2v-v2wh
Affected version: >=4.0.0-RC1,<=4.17.8|>=5.0.0-RC1,<=5.9.14
Reported by:
GitHub -
[MEDIUM] Server-Side Request Forgery (SSRF) in Craft CMS with Asset Uploads Mutations
PKSA-wb3t-ts8t-d4cj CVE-2026-41129 GHSA-3m9m-24vh-39wx
Affected version: >=4.0.0-RC1,<=4.17.8|>=5.0.0-RC1,<=5.9.14
Reported by:
GitHub -
[MEDIUM] Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action
PKSA-dmwd-n76s-m3f9 CVE-2026-41128 GHSA-jq2f-59pj-p3m3
Affected version: >=5.6.0,<5.9.15
Reported by:
GitHub -
[LOW] Craft CMS: Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata
PKSA-hq3k-cthz-b9zn CVE-2026-56385 GHSA-44px-qjjc-xrhq
Affected version: >=4.0.0-RC1,<=4.17.7|>=5.0.0-RC1,<=5.9.13
Reported by:
GitHub -
[MEDIUM] Craft CMS has an authorization bypass which allows any control panel user to move entries without permissions
PKSA-7c6f-2hwc-ptwd CVE-2026-33162 GHSA-f582-6gf6-gx4g
Affected version: >=5.3.0,<=5.9.13
Reported by:
GitHub -
[LOW] Craft CMS' anonymous "assets/image-editor" calls return private asset editor metadata to unauthorized users
PKSA-w984-dygq-7ryn CVE-2026-33161 GHSA-vgjg-248p-rfm2
Affected version: >=4.0.0-RC1,<=4.17.7|>=5.0.0-RC1,<=5.9.13
Reported by:
GitHub -
[LOW] Craft CMS may expose private assets through anonymous "generate transform" calls via transform URL
PKSA-swp1-ty4d-gpzy CVE-2026-33160 GHSA-5pgf-h923-m958
Affected version: >=4.0.0-RC1,<=4.17.7|>=5.0.0-RC1,<=5.9.13
Reported by:
GitHub -
[MEDIUM] Craft CMS: Unauthenticated Users Can Perform Restricted Project Config Sync Operations
PKSA-rxrx-pcy1-2csw CVE-2026-33159 GHSA-6mrr-q3pj-h53w
Affected version: >=4.0.0-RC1,<=4.17.7|>=5.0.0-RC1,<=5.9.13
Reported by:
GitHub -
[MEDIUM] Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)
PKSA-548y-fsbg-y9t7 CVE-2026-33158 GHSA-3pvf-vxrv-hh9c
Affected version: >=5.0.0-RC1,<=5.9.13|>=4.0.0-RC1,<=4.17.7
Reported by:
GitHub