Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-hf67-x9c8-783j |
|
MINI-hf67-x9c8-783j |
| MINI-hx7x-xj5j-3xr5 |
|
MINI-hx7x-xj5j-3xr5 |
| CVE-2026-56397 |
|
Cross-Site Scripting (XSS) in CVE-2026-56397 (CVE-2026-56397)
cross-site scripting in CVE-2026-56397 (CVE-2026-56397). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56396 |
|
Vulnerability in CVE-2026-56396 (CVE-2026-56396)
vulnerability in CVE-2026-56396 (CVE-2026-56396). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56395 |
|
Cross-Site Scripting (XSS) in CVE-2026-56395 (CVE-2026-56395)
cross-site scripting in CVE-2026-56395 (CVE-2026-56395). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56394 |
|
Path Traversal in craftcms/cms (CVE-2026-56394)
path traversal in craftcms/cms (CVE-2026-56394). Confidential information can be exposed externally. Exploitable via ``extension``. Mitigation: upgrade to `5.9.13` or later.
|
| CVE-2026-56393 |
|
Cross-Site Scripting (XSS) in craftcms/cms (CVE-2026-56393)
cross-site scripting in craftcms/cms (CVE-2026-56393). Risk of unauthorized operations or information disclosure. Exploitable via ``checkbox.twig``. Mitigation: upgrade to `4.17.0-beta.1` or later.
|
| CVE-2026-56385 |
|
Information Disclosure in craftcms/cms (CVE-2026-56385)
vulnerability in craftcms/cms (CVE-2026-56385). Risk of unauthorized operations or information disclosure. Exploitable via ``previewHtml``. Mitigation: upgrade to `4.17.8` or later.
|
| CVE-2026-56384 |
|
Information Disclosure in craftcms/cms (CVE-2026-56384)
vulnerability in craftcms/cms (CVE-2026-56384). Risk of unauthorized operations or information disclosure. Exploitable via ``assetId``. Mitigation: upgrade to `5.9.14` or later.
|
| CVE-2026-56383 |
|
Cross-Site Scripting (XSS) in craftcms/cms (CVE-2026-56383)
cross-site scripting in craftcms/cms (CVE-2026-56383). Risk of unauthorized operations or information disclosure. Exploitable via ``editableTable.twig``. Mitigation: upgrade to `5.8.23` or later.
|
| CVE-2026-56382 |
|
Code Injection in craftcms/cms (CVE-2026-56382)
code injection in craftcms/cms (CVE-2026-56382). Successful exploitation can lead to full system takeover. Exploitable via `POST /admin/actions/fields/render-card-preview`. Mitigation: upgrade to `5.9.14` or later.
|
| CVE-2026-56381 |
|
Cross-Site Scripting (XSS) in craftcms/cms (CVE-2026-56381)
cross-site scripting in craftcms/cms (CVE-2026-56381). Risk of unauthorized operations or information disclosure. Exploitable via ``allowAdminChanges``. Mitigation: upgrade to `5.8.22` or later.
|
| CVE-2026-56378 |
|
Out-of-Bounds Read in dos (CVE-2026-56378)
vulnerability in dos (CVE-2026-56378). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56367 |
|
Out-of-Bounds Read in c (CVE-2026-56367)
vulnerability in c (CVE-2026-56367). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56316 |
|
Vulnerability in CVE-2026-56316 (CVE-2026-56316)
vulnerability in CVE-2026-56316 (CVE-2026-56316). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56299 |
|
Vulnerability in dos (CVE-2026-56299)
vulnerability in dos (CVE-2026-56299). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56265 |
|
Vulnerability in kidocode (CVE-2026-56265)
vulnerability in kidocode (CVE-2026-56265). Successful exploitation can lead to full system takeover.
|
| CVE-2026-56253 |
|
Vulnerability in CVE-2026-56253 (CVE-2026-56253)
vulnerability in CVE-2026-56253 (CVE-2026-56253). Confidential information can be exposed externally.
|
| CVE-2026-56251 |
|
Vulnerability in CVE-2026-56251 (CVE-2026-56251)
vulnerability in CVE-2026-56251 (CVE-2026-56251). Data can be tampered with by attackers.
|
| CVE-2026-56242 |
|
Information Disclosure in CVE-2026-56242 (CVE-2026-56242)
vulnerability in CVE-2026-56242 (CVE-2026-56242). Confidential information can be exposed externally.
|
| CVE-2026-56239 |
|
Privilege Escalation in privilege-escalation (CVE-2026-56239)
vulnerability in privilege-escalation (CVE-2026-56239). Data can be tampered with by attackers.
|
| CVE-2026-56236 |
|
Vulnerability in CVE-2026-56236 (CVE-2026-56236)
vulnerability in CVE-2026-56236 (CVE-2026-56236). Data can be tampered with by attackers.
|
| CVE-2026-56229 |
|
Vulnerability in CVE-2026-56229 (CVE-2026-56229)
vulnerability in CVE-2026-56229 (CVE-2026-56229). Confidential information can be exposed externally.
|
| CVE-2025-71378 |
|
Unsafe Deserialization in picklescan (CVE-2025-71378)
vulnerability in picklescan (CVE-2025-71378). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.30` or later.
|
| CVE-2025-71357 |
|
Unsafe Deserialization in picklescan (CVE-2025-71357)
vulnerability in picklescan (CVE-2025-71357). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.30` or later.
|
| CVE-2025-71351 |
|
Vulnerability in CVE-2025-71351 (CVE-2025-71351)
vulnerability in CVE-2025-71351 (CVE-2025-71351). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-71348 |
|
Vulnerability in picklescan (CVE-2025-71348)
vulnerability in picklescan (CVE-2025-71348). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.28` or later.
|
| MINI-fj6x-rrhh-2wcq |
|
MINI-fj6x-rrhh-2wcq |
| MINI-9v3c-p39h-j472 |
|
MINI-9v3c-p39h-j472 |
| MINI-5wfw-h46w-v3p9 |
|
MINI-5wfw-h46w-v3p9 |
| MINI-qwwr-58hp-3wqf |
|
MINI-qwwr-58hp-3wqf |
| MINI-w3m5-7r3p-7qwh |
|
MINI-w3m5-7r3p-7qwh |
| MINI-ffph-jp34-r68x |
|
MINI-ffph-jp34-r68x |
| MINI-jpjv-5c3p-jm79 |
|
MINI-jpjv-5c3p-jm79 |
| MINI-65c8-wp6w-vg26 |
|
MINI-65c8-wp6w-vg26 |
| MINI-4gqf-rq6f-vj7w |
|
MINI-4gqf-rq6f-vj7w |
| MINI-m8hg-4w27-fqj6 |
|
MINI-m8hg-4w27-fqj6 |
| MINI-j2hq-8c4h-mcm9 |
|
MINI-j2hq-8c4h-mcm9 |
| MINI-9m4h-v755-mv8m |
|
MINI-9m4h-v755-mv8m |
| MINI-ff8r-g953-33mg |
|
MINI-ff8r-g953-33mg |
| MINI-hc52-fv33-cwvf |
|
MINI-hc52-fv33-cwvf |
| MINI-gc24-wqh2-4hr3 |
|
MINI-gc24-wqh2-4hr3 |
| MINI-6pfm-qxjq-356f |
|
MINI-6pfm-qxjq-356f |
| MINI-h8q5-q7p7-5v8g |
|
MINI-h8q5-q7p7-5v8g |
| MINI-f877-jgw3-jv2f |
|
MINI-f877-jgw3-jv2f |
| MINI-6w8q-w9m9-8j7f |
|
MINI-6w8q-w9m9-8j7f |
| MINI-64cc-9p7g-35f8 |
|
MINI-64cc-9p7g-35f8 |
| MINI-5jx9-wr3m-3cpg |
|
MINI-5jx9-wr3m-3cpg |
| MINI-89gw-67v3-pmx5 |
|
MINI-89gw-67v3-pmx5 |
| MINI-fwmr-qhfx-2vhh |
|
MINI-fwmr-qhfx-2vhh |