Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Craftercms

First CVE: Dec 6, 2018Active for: 8 yearsTotal CVEs: 28
44.3
VTI Score
High

Craftercms operates a modestly represented, web-based content management system that serves as the central integration point for content authoring, publishing, and site delivery, positioning it as a critical application layer in customer environments. Vulnerabilities affecting this platform skew toward serious outcomes, with an elevated share reaching critical severity, and cluster persistently around code execution and input-handling weaknesses: improper control of dynamically-managed code resources, cross-site scripting, path traversal, and resource-exposure flaws that reflect the risks inherent to templating engines and user-controlled content pipelines. The exposure concentrates in Crafter CMS and Studio, the primary authoring and administrative components, where these weakness classes recur across multiple versions and create both direct attack surface and downstream risk to published content. Defenders should prioritize patching this vendor's advisories for internet-facing or multi-tenant deployments and audit custom templates and extensions for injection and traversal patterns; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 75% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Craftercms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 6, 2018
7 years ago
Most Recent CVE
Feb 2, 2026
172 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-15681CRITICAL
In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to
Nov 27, 20209.832NONO
CVE-2021-23264CRITICAL
Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes.
Dec 2, 20219.130NONO
CVE-2017-15685HIGH
Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieva
Nov 27, 20208.629NONO
CVE-2017-15683HIGH
In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band.
Nov 27, 20208.629NONO
CVE-2025-6384CRITICAL
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypas
Jun 19, 20259.128NONO
CVE-2023-4136MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected
Aug 3, 20236.128NOYES
CVE-2021-23267HIGH
Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker static m
May 16, 20228.828NONO
CVE-2017-15684HIGH
Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view files from the operating system.
Nov 27, 20207.527NONO
CVE-2018-19907HIGH
A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl f
Dec 6, 20188.827NONO
CVE-2021-23263HIGH
Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary).
Dec 2, 20217.525NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
36%
50%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network28 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (96.4%)
High1 (3.6%)
Unknown0 (0.0%)
User Interaction
None22 (78.6%)
Unknown0 (0.0%)
Required6 (21.4%)
Privileges Required
Low4 (14.3%)
High12 (42.9%)
None12 (42.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.6% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Craftercms.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Craftercms — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Craftercms's Products

View all 3 CNAs →

Top CWEs