CraftCMS 漏洞列表
共找到 8 个与 CraftCMS 相关的漏洞
📅 加载漏洞趋势中...
-
CVE-2023-41892: CraftCMS < 4.4.15 - Unauthenticated Remote Code Execution POC
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector leading to Remote Code Execution (RCE). Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15. FOFA: icon_hash="-47932290" -
CVE-2021-41749: CraftCMS SEOmatic - Server-Side Template Injection POC
In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side. Template Injection, allowing for remote code execution. -
CVE-2023-41892: CraftCMS < 4.4.15 - Unauthenticated Remote Code Execution POC
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector leading to Remote Code Execution (RCE). Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15. -
CVE-2025-32432: CraftCMS - Remote Code Execution POC
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. -
CraftCms 代码注入漏洞(CVE-2025-32432) 无POC
攻击者可构造恶意请求利用generate-transform端点触发反序列化,执行任意代码控制服务器,未经身份验证的攻击者可以通过该漏洞在目标服务器上注入恶意代码,最终获取服务器权限。 -
CraftCMS /ConditionsController.php 代码执行漏洞(CVE-2023-41892) 无POC
Craft CMS是一个开源的内容管理系统,它专注于用户友好的内容创建过程,逻辑清晰明了,是一个高度自由,高度自定义设计的平台吗,可以用来创建个人或企业网站也可以搭建企业级电子商务系统。Craft CMS在4.4.15版本之前存在远程代码执行漏洞,攻击者可构造恶意请求执行任意代码,控制服务器。影响版本 :4.0.0-RC1 <= Craft CMS <= 4.4.14 -
CraftCMS SEOmatic 模板注入漏洞(CVE-2021-41749) 无POC
在Craft CMS 3高达3.4.11的SEOmatic插件中,未经身份验证的攻击者可以执行服务器端。模板注入,允许远程代码执行。 -
CraftCMS 远程代码执行漏洞(CVE-2020-9757) 无POC
CraftCMS是一个既优雅又强大的PHP商业开源系统,是大多数五百强公司首选内容管理系统加品牌自营电商解决方案。其存在远程代码执行漏洞,攻击者可以获取服务器权限。