Vulnerabilities
Vulnerable Software
Craftcms:  >> Craft Cms  >> 3.9.11  Security Vulnerabilities
Craft CMS through 4.4.9 is vulnerable to HTML Injection.
CVSS Score
6.1
EPSS Score
0.002
Published
2023-06-20
Craft is a CMS for creating custom digital experiences on the web. Cross-site scripting (XSS) can be triggered via the Update Asset Index utility. This issue has been patched in version 4.4.6.
CVSS Score
5.5
EPSS Score
0.004
Published
2023-05-26
A post-authentication stored cross-site scripting vulnerability exists in Craft CMS versions <= 4.4.11. HTML, including script tags can be injected into field names which, when the field is added to a category or section, will trigger when users visit the Categories or Entries pages respectively.
CVSS Score
5.4
EPSS Score
0.002
Published
2023-05-26
Craft is a platform for creating digital experiences. When you insert a payload inside a label name or instruction of an entry type, an cross-site scripting (XSS) happens in the quick post widget on the admin dashboard. This issue has been fixed in version 4.3.7.
CVSS Score
6.1
EPSS Score
0.027
Published
2023-03-03


Contact Us

Shodan ® - All rights reserved