Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
MINI-hf67-x9c8-783j MINI-hf67-x9c8-783j
MINI-hx7x-xj5j-3xr5 MINI-hx7x-xj5j-3xr5
CVE-2026-56397 Cross-Site Scripting (XSS) in CVE-2026-56397 (CVE-2026-56397)
cross-site scripting in CVE-2026-56397 (CVE-2026-56397). Successful exploitation can lead to full system takeover.
CVE-2026-56396 Vulnerability in CVE-2026-56396 (CVE-2026-56396)
vulnerability in CVE-2026-56396 (CVE-2026-56396). Successful exploitation can lead to full system takeover.
CVE-2026-56395 Cross-Site Scripting (XSS) in CVE-2026-56395 (CVE-2026-56395)
cross-site scripting in CVE-2026-56395 (CVE-2026-56395). Successful exploitation can lead to full system takeover.
CVE-2026-56394 Path Traversal in craftcms/cms (CVE-2026-56394)
path traversal in craftcms/cms (CVE-2026-56394). Confidential information can be exposed externally. Exploitable via ``extension``. Mitigation: upgrade to `5.9.13` or later.
CVE-2026-56393 Cross-Site Scripting (XSS) in craftcms/cms (CVE-2026-56393)
cross-site scripting in craftcms/cms (CVE-2026-56393). Risk of unauthorized operations or information disclosure. Exploitable via ``checkbox.twig``. Mitigation: upgrade to `4.17.0-beta.1` or later.
CVE-2026-56385 Information Disclosure in craftcms/cms (CVE-2026-56385)
vulnerability in craftcms/cms (CVE-2026-56385). Risk of unauthorized operations or information disclosure. Exploitable via ``previewHtml``. Mitigation: upgrade to `4.17.8` or later.
CVE-2026-56384 Information Disclosure in craftcms/cms (CVE-2026-56384)
vulnerability in craftcms/cms (CVE-2026-56384). Risk of unauthorized operations or information disclosure. Exploitable via ``assetId``. Mitigation: upgrade to `5.9.14` or later.
CVE-2026-56383 Cross-Site Scripting (XSS) in craftcms/cms (CVE-2026-56383)
cross-site scripting in craftcms/cms (CVE-2026-56383). Risk of unauthorized operations or information disclosure. Exploitable via ``editableTable.twig``. Mitigation: upgrade to `5.8.23` or later.
CVE-2026-56382 Code Injection in craftcms/cms (CVE-2026-56382)
code injection in craftcms/cms (CVE-2026-56382). Successful exploitation can lead to full system takeover. Exploitable via `POST /admin/actions/fields/render-card-preview`. Mitigation: upgrade to `5.9.14` or later.
CVE-2026-56381 Cross-Site Scripting (XSS) in craftcms/cms (CVE-2026-56381)
cross-site scripting in craftcms/cms (CVE-2026-56381). Risk of unauthorized operations or information disclosure. Exploitable via ``allowAdminChanges``. Mitigation: upgrade to `5.8.22` or later.
CVE-2026-56378 Out-of-Bounds Read in dos (CVE-2026-56378)
vulnerability in dos (CVE-2026-56378). Risk of unauthorized operations or information disclosure.
CVE-2026-56367 Out-of-Bounds Read in c (CVE-2026-56367)
vulnerability in c (CVE-2026-56367). Risk of unauthorized operations or information disclosure.
CVE-2026-56316 Vulnerability in CVE-2026-56316 (CVE-2026-56316)
vulnerability in CVE-2026-56316 (CVE-2026-56316). Risk of unauthorized operations or information disclosure.
CVE-2026-56299 Vulnerability in dos (CVE-2026-56299)
vulnerability in dos (CVE-2026-56299). Risk of unauthorized operations or information disclosure.
CVE-2026-56265 Vulnerability in kidocode (CVE-2026-56265)
vulnerability in kidocode (CVE-2026-56265). Successful exploitation can lead to full system takeover.
CVE-2026-56253 Vulnerability in CVE-2026-56253 (CVE-2026-56253)
vulnerability in CVE-2026-56253 (CVE-2026-56253). Confidential information can be exposed externally.
CVE-2026-56251 Vulnerability in CVE-2026-56251 (CVE-2026-56251)
vulnerability in CVE-2026-56251 (CVE-2026-56251). Data can be tampered with by attackers.
CVE-2026-56242 Information Disclosure in CVE-2026-56242 (CVE-2026-56242)
vulnerability in CVE-2026-56242 (CVE-2026-56242). Confidential information can be exposed externally.
CVE-2026-56239 Privilege Escalation in privilege-escalation (CVE-2026-56239)
vulnerability in privilege-escalation (CVE-2026-56239). Data can be tampered with by attackers.
CVE-2026-56236 Vulnerability in CVE-2026-56236 (CVE-2026-56236)
vulnerability in CVE-2026-56236 (CVE-2026-56236). Data can be tampered with by attackers.
CVE-2026-56229 Vulnerability in CVE-2026-56229 (CVE-2026-56229)
vulnerability in CVE-2026-56229 (CVE-2026-56229). Confidential information can be exposed externally.
CVE-2025-71378 Unsafe Deserialization in picklescan (CVE-2025-71378)
vulnerability in picklescan (CVE-2025-71378). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.30` or later.
CVE-2025-71357 Unsafe Deserialization in picklescan (CVE-2025-71357)
vulnerability in picklescan (CVE-2025-71357). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.30` or later.
CVE-2025-71351 Vulnerability in CVE-2025-71351 (CVE-2025-71351)
vulnerability in CVE-2025-71351 (CVE-2025-71351). Risk of unauthorized operations or information disclosure.
CVE-2025-71348 Vulnerability in picklescan (CVE-2025-71348)
vulnerability in picklescan (CVE-2025-71348). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.0.28` or later.
MINI-fj6x-rrhh-2wcq MINI-fj6x-rrhh-2wcq
MINI-9v3c-p39h-j472 MINI-9v3c-p39h-j472
MINI-5wfw-h46w-v3p9 MINI-5wfw-h46w-v3p9
MINI-qwwr-58hp-3wqf MINI-qwwr-58hp-3wqf
MINI-w3m5-7r3p-7qwh MINI-w3m5-7r3p-7qwh
MINI-ffph-jp34-r68x MINI-ffph-jp34-r68x
MINI-jpjv-5c3p-jm79 MINI-jpjv-5c3p-jm79
MINI-65c8-wp6w-vg26 MINI-65c8-wp6w-vg26
MINI-4gqf-rq6f-vj7w MINI-4gqf-rq6f-vj7w
MINI-m8hg-4w27-fqj6 MINI-m8hg-4w27-fqj6
MINI-j2hq-8c4h-mcm9 MINI-j2hq-8c4h-mcm9
MINI-9m4h-v755-mv8m MINI-9m4h-v755-mv8m
MINI-ff8r-g953-33mg MINI-ff8r-g953-33mg
MINI-hc52-fv33-cwvf MINI-hc52-fv33-cwvf
MINI-gc24-wqh2-4hr3 MINI-gc24-wqh2-4hr3
MINI-6pfm-qxjq-356f MINI-6pfm-qxjq-356f
MINI-h8q5-q7p7-5v8g MINI-h8q5-q7p7-5v8g
MINI-f877-jgw3-jv2f MINI-f877-jgw3-jv2f
MINI-6w8q-w9m9-8j7f MINI-6w8q-w9m9-8j7f
MINI-64cc-9p7g-35f8 MINI-64cc-9p7g-35f8
MINI-5jx9-wr3m-3cpg MINI-5jx9-wr3m-3cpg
MINI-89gw-67v3-pmx5 MINI-89gw-67v3-pmx5
MINI-fwmr-qhfx-2vhh MINI-fwmr-qhfx-2vhh

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →