Craftcms maintains a focused web content management and e-commerce platform whose narrow product footprint belies substantial prominence in the landscape, reflecting deep adoption across publishing, agency, and retail deployment contexts. Vulnerabilities affecting the vendor skew toward moderate severity and have a moderate tendency to acquire public exploit code; the exposure concentrates in Craft CMS and Craft Commerce and recurs through application-layer weakness classes including cross-site scripting, code injection, SQL injection, and authorization bypass through user-controlled keys, reflecting the parsing and template-rendering demands of a content-management system. These weakness classes are characteristic of web applications handling user input and dynamic template generation, and remediation typically depends on the vendor's patching cadence and downstream deployment of updates. Defenders tracking this vendor should prioritize internet-facing Craft instances and review custom extensions for input-handling rigor; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Craftcms over time
Signals from CVEs in this vendor scope (114 CVEs).
114 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-32432CRITICAL Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, | Apr 25, 2025 | 10.0 | 99 | YES | YES |
CVE-2024-56145CRITICAL Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini | Dec 18, 2024 | 9.8 | 98 | YES | YES |
CVE-2023-41892CRITICAL Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to upd | Sep 13, 2023 | 9.8 | 90 | NO | YES |
CVE-2020-9757CRITICAL The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller. | Mar 4, 2020 | 9.8 | 81 | NO | YES |
CVE-2025-23209HIGH Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and | Jan 18, 2025 | 8.1 | 67 | YES | NO |
CVE-2024-37843CRITICAL Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint. | Jun 25, 2024 | 9.8 | 66 | NO | YES |
CVE-2025-35939MEDIUM Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Cra | May 7, 2025 | 5.3 | 57 | YES | NO |
CVE-2026-32267CRITICAL Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an una | Mar 16, 2026 | 9.8 | 38 | NO | NO |
CVE-2025-68456CRITICAL Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations | Jan 5, 2026 | 9.1 | 32 | NO | NO |
CVE-2019-14280MEDIUM In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/ | Jul 26, 2019 | 5.3 | 32 | NO | YES |
Signals from CVEs in this vendor scope (114 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Craftcms.
Media articles that mention a CVE ID that affects a product developed by Craftcms — matched by CVE ID, not by vendor name.