Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Craftcms

First CVE: Apr 22, 2017Active for: 9 yearsTotal CVEs: 114
68.4
VTI Score
TOP TARGET

Craftcms maintains a focused web content management and e-commerce platform whose narrow product footprint belies substantial prominence in the landscape, reflecting deep adoption across publishing, agency, and retail deployment contexts. Vulnerabilities affecting the vendor skew toward moderate severity and have a moderate tendency to acquire public exploit code; the exposure concentrates in Craft CMS and Craft Commerce and recurs through application-layer weakness classes including cross-site scripting, code injection, SQL injection, and authorization bypass through user-controlled keys, reflecting the parsing and template-rendering demands of a content-management system. These weakness classes are characteristic of web applications handling user input and dynamic template generation, and remediation typically depends on the vendor's patching cadence and downstream deployment of updates. Defenders tracking this vendor should prioritize internet-facing Craft instances and review custom extensions for input-handling rigor; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
114
Total CVEs
More Total CVEs than 99% of tracked vendors
5.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.6
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
3.5%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Craftcms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 22, 2017
9 years ago
Most Recent CVE
Mar 24, 2026
122 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (114 CVEs).

114 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-32432CRITICAL
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15,
Apr 25, 202510.099YESYES
CVE-2024-56145CRITICAL
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini
Dec 18, 20249.898YESYES
CVE-2023-41892CRITICAL
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to upd
Sep 13, 20239.890NOYES
CVE-2020-9757CRITICAL
The SEOmatic component before 3.3.0 for Craft CMS allows Server-Side Template Injection that leads to RCE via malformed data to the metacontainers controller.
Mar 4, 20209.881NOYES
CVE-2025-23209HIGH
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and
Jan 18, 20258.167YESNO
CVE-2024-37843CRITICAL
Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.
Jun 25, 20249.866NOYES
CVE-2025-35939MEDIUM
Craft CMS stores arbitrary content provided by unauthenticated users in session files. This content could be accessed and executed, possibly using an independent vulnerability. Cra
May 7, 20255.357YESNO
CVE-2026-32267CRITICAL
Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.6 and from version 5.0.0-RC1 to before version 5.9.12, a low-privilege user (or an una
Mar 16, 20269.838NONO
CVE-2025-68456CRITICAL
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, unauthenticated users can trigger database backup operations
Jan 5, 20269.132NONO
CVE-2019-14280MEDIUM
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images when it was configured to do so, potentially exposing personal/
Jul 26, 20195.332NOYES
View all 114 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products114 CVEs
61%
29%
10%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network114 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low110 (96.5%)
High4 (3.5%)
Unknown0 (0.0%)
User Interaction
None63 (55.3%)
Unknown0 (0.0%)
Required51 (44.7%)
Privileges Required
Low38 (33.3%)
High36 (31.6%)
None40 (35.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (114 CVEs).

CISA KEV
4 CVEs
3.5% of CVEs· 99th percentile
Metasploit
3 CVEs
2.6% of CVEs· 97th percentile
Nuclei
5 CVEs
4.4% of CVEs· 95th percentile
ExploitDB
5 CVEs
4.4% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Craftcms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Craftcms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Craftcms's Products

View all 4 CNAs →

Top CWEs