Crafter CMS
First CVE: Oct 6, 2020Active for: 6 years
19
CVEs Published
More CVEs Published than 38% of tracked CNAs
3.2
Avg CVEs / Year
More Avg CVEs / Year than 23% of tracked CNAs
6.9
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by Crafter CMS over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 6, 2020
5 years ago
Most Recent CVE
Feb 2, 2026
172 days ago
Top CVEs
All CVEs published by Crafter CMS as a CNA, regardless of affected vendor or product.
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-23264CRITICAL Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes. | Dec 2, 2021 | 9.1 | 30 | NO | NO |
CVE-2025-6384CRITICAL Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypas | Jun 19, 2025 | 9.1 | 28 | NO | NO |
CVE-2023-4136MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected | Aug 3, 2023 | 6.1 | 28 | NO | YES |
CVE-2021-23267HIGH Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker static m | May 16, 2022 | 8.8 | 28 | NO | NO |
CVE-2021-23263HIGH Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary). | Dec 2, 2021 | 7.5 | 25 | NO | NO |
CVE-2025-0502CRITICAL Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS, x86, Windows, 64 bit, ARM allows Directory Indexing, Resou | Jan 15, 2025 | 9.1 | 24 | NO | NO |
CVE-2022-40635HIGH Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypa | Sep 13, 2022 | 7.2 | 24 | NO | NO |
CVE-2021-23259HIGH Authenticated users with Administrator or Developer roles may execute OS commands by Groovy Script which uses Groovy lib to render a webpage. The groovy script does not have securi | Dec 2, 2021 | 7.2 | 24 | NO | NO |
CVE-2022-40634HIGH Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker SSTI. | Sep 13, 2022 | 7.2 | 23 | NO | NO |
CVE-2021-23262HIGH Authenticated administrators may modify the main YAML configuration file and load a Java class resulting in RCE. | Dec 2, 2021 | 7.2 | 23 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA19 CVEs
32%
53%
16%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network19 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (94.7%)
High1 (5.3%)
Unknown0 (0.0%)
User Interaction
None16 (84.2%)
Unknown0 (0.0%)
Required3 (15.8%)
Privileges Required
Low3 (15.8%)
High11 (57.9%)
None5 (26.3%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (19 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.3% of CVEs· 93rd percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Crafter CMS as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Crafter CMS as a CNA — matched by CVE ID, not by organization name.