Craftercms operates a modestly represented, web-based content management system that serves as the central integration point for content authoring, publishing, and site delivery, positioning it as a critical application layer in customer environments. Vulnerabilities affecting this platform skew toward serious outcomes, with an elevated share reaching critical severity, and cluster persistently around code execution and input-handling weaknesses: improper control of dynamically-managed code resources, cross-site scripting, path traversal, and resource-exposure flaws that reflect the risks inherent to templating engines and user-controlled content pipelines. The exposure concentrates in Crafter CMS and Studio, the primary authoring and administrative components, where these weakness classes recur across multiple versions and create both direct attack surface and downstream risk to published content. Defenders should prioritize patching this vendor's advisories for internet-facing or multi-tenant deployments and audit custom templates and extensions for injection and traversal patterns; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Craftercms over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15681CRITICAL In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to | Nov 27, 2020 | 9.8 | 32 | NO | NO |
CVE-2021-23264CRITICAL Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes. | Dec 2, 2021 | 9.1 | 30 | NO | NO |
CVE-2017-15685HIGH Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieva | Nov 27, 2020 | 8.6 | 29 | NO | NO |
CVE-2017-15683HIGH In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band. | Nov 27, 2020 | 8.6 | 29 | NO | NO |
CVE-2025-6384CRITICAL Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypas | Jun 19, 2025 | 9.1 | 28 | NO | NO |
CVE-2023-4136MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected | Aug 3, 2023 | 6.1 | 28 | NO | YES |
CVE-2021-23267HIGH Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker static m | May 16, 2022 | 8.8 | 28 | NO | NO |
CVE-2017-15684HIGH Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view files from the operating system. | Nov 27, 2020 | 7.5 | 27 | NO | NO |
CVE-2018-19907HIGH A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl f | Dec 6, 2018 | 8.8 | 27 | NO | NO |
CVE-2021-23263HIGH Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary). | Dec 2, 2021 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Craftercms.
Media articles that mention a CVE ID that affects a product developed by Craftercms — matched by CVE ID, not by vendor name.