Crafter Cms
Vendor:
First CVE: Dec 6, 2018 · Active for 7 years
28
Total CVEs
More Total CVEs than 96% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Crafter Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 6, 2018
7 years ago
Most Recent CVE
Feb 2, 2026
176 days ago
CVE Severity & Scoring
Crafter Cms28 CVEs
36%
50%
14%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network28 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (96.4%)
High1 (3.6%)
Unknown0 (0.0%)
User Interaction
None22 (78.6%)
Unknown0 (0.0%)
Required6 (21.4%)
Privileges Required
Low4 (14.3%)
High12 (42.9%)
None12 (42.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15681CRITICAL In Crafter CMS Crafter Studio 3.0.1 a directory traversal vulnerability exists which allows unauthenticated attackers to overwrite files from the operating system which can lead to | Nov 27, 2020 | 9.8 | 32 | NO | NO |
CVE-2021-23264CRITICAL Installations, where crafter-search is not protected, allow unauthenticated remote attackers to create, view, and delete search indexes. | Dec 2, 2021 | 9.1 | 30 | NO | NO |
CVE-2017-15685HIGH Crafter CMS Crafter Studio 3.0.1 is affected by: XML External Entity (XXE). An unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieva | Nov 27, 2020 | 8.6 | 29 | NO | NO |
CVE-2017-15683HIGH In Crafter CMS Crafter Studio 3.0.1 an unauthenticated attacker is able to create a site with specially crafted XML that allows the retrieval of OS files out-of-band. | Nov 27, 2020 | 8.6 | 29 | NO | NO |
CVE-2025-6384CRITICAL Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of CrafterCMS allows authenticated developers to execute OS commands via Groovy Sandbox Bypas | Jun 19, 2025 | 9.1 | 28 | NO | NO |
CVE-2023-4136MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine on Windows, MacOS, Linux, x86, ARM, 64 bit allows Reflected | Aug 3, 2023 | 6.1 | 28 | NO | YES |
CVE-2021-23267HIGH Improper Control of Dynamically-Managed Code Resources vulnerability in Crafter Studio of Crafter CMS allows authenticated developers to execute OS commands via FreeMarker static m | May 16, 2022 | 8.8 | 28 | NO | NO |
CVE-2017-15684HIGH Crafter CMS Crafter Studio 3.0.1 has a directory traversal vulnerability which allows unauthenticated attackers to view files from the operating system. | Nov 27, 2020 | 7.5 | 27 | NO | NO |
CVE-2018-19907HIGH A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may execute OS commands by Creating/Editing a template file (.ftl f | Dec 6, 2018 | 8.8 | 27 | NO | NO |
CVE-2021-23263HIGH Unauthenticated remote attackers can read textual content via FreeMarker including files /scripts/*, /templates/* and some of the files in /.git/* (non-binary). | Dec 2, 2021 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (28 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
3.6% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (28 CVEs).
Media Mentions
Signals from CVEs in this product scope (28 CVEs).
Top CNAs Publishing CVEs For Crafter Cms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.0.0 | 1 | 4.8 | 0.6% | 0 | 0 |