Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

craftcms

About This Vendor

craftcms is a technology vendor producing software and infrastructure products. As a software provider, craftcms's broad product portfolio across multiple domains—including operating systems, cloud infrastructure, enterprise applications, databases, networking, and security tools—creates a large attack surface. Additionally, long support cycles, widespread deployment, and continuous feature development contribute to the accumulation of discovered vulnerabilities over time. Major vendors typically report higher CVE counts not necessarily due to inferior security, but because of greater exposure to security research, responsible disclosure practices, and the sheer complexity of maintaining multiple product lines and legacy systems. Regular security assessments and patching of craftcms's products are critical for organizations running their software in production environments.

Vulnerability Trends for This Vendor

SecUtils has indexed 118 known vulnerabilities from craftcms. This includes 11 critical-severity issues and 32 high-severity issues that represent significant risk. These vulnerabilities affect 3 distinct products across craftcms's portfolio, demonstrating the breadth of the vendor's product ecosystem and the importance of comprehensive patch management strategies. Disclosure dates span from 2017 through 2026, reflecting sustained security scrutiny over multiple years. Organizations deploying craftcms products should maintain active vulnerability monitoring, prioritize critical patches, and implement compensating controls where patches cannot be applied immediately.

ID Date Published Last Modified Severity (CVSSv3) Severity (CVSSv2) Exploit Available
CVE-2017-8052 2017-04-22 2026-06-17 6.1 4.3 Likely
CVE-2017-8383 2017-05-01 2026-06-17 5.3 5.0 Likely
CVE-2017-8384 2017-05-01 2026-06-17 6.1 4.3 Likely
CVE-2017-8385 2017-05-01 2026-06-17 5.3 5.0 Likely
CVE-2017-9516 2017-06-08 2026-06-17 5.4 3.5 Unknown
CVE-2018-3814 2018-01-01 2026-06-17 8.8 6.5 Likely
CVE-2018-20418 2018-12-24 2026-06-17 4.8 3.5 Unknown
CVE-2018-20465 2018-12-25 2026-06-17 7.2 4.0 Likely
CVE-2019-12823 2019-06-18 2026-06-17 6.1 4.3 Likely
CVE-2019-14280 2019-07-26 2026-06-17 5.3 5.0 Likely
CVE-2019-17496 2019-10-11 2026-06-17 6.1 4.3 Likely
CVE-2019-15929 2019-10-24 2026-06-17 9.8 5.0 Likely
CVE-2019-9554 2019-12-31 2026-06-17 6.1 4.3 Likely
CVE-2020-9757 2020-03-04 2026-06-17 9.8 7.5 Likely
CVE-2020-19626 2021-03-26 2026-06-17 5.4 3.5 Unknown
CVE-2021-32470 2021-05-07 2026-06-17 6.1 4.3 Likely
CVE-2021-27902 2021-06-30 2026-06-17 6.1 4.3 Likely
CVE-2021-27903 2021-06-30 2026-06-17 9.8 7.5 Likely
CVE-2021-41824 2021-09-30 2026-06-17 8.8 6.8 Likely
CVE-2022-28378 2022-04-03 2026-06-17 6.1 4.3 Likely
CVE-2022-29933 2022-05-09 2026-06-17 8.8 6.8 Likely
CVE-2022-37250 2022-09-16 2026-06-17 5.4 - -
CVE-2022-37248 2022-09-16 2026-06-17 5.4 - -
CVE-2022-37247 2022-09-16 2026-06-17 5.4 - -
CVE-2022-37251 2022-09-16 2026-07-09 5.4 - -
CVE-2022-37246 2022-09-21 2026-06-17 5.4 - -
CVE-2022-37783 2022-12-05 2026-06-17 7.5 - -
CVE-2023-23927 2023-03-03 2026-06-17 6.1 - -
CVE-2023-30177 2023-04-25 2026-06-17 6.1 - -
CVE-2023-31144 2023-05-09 2026-06-17 6.1 - -
CVE-2023-30130 2023-05-12 2026-06-17 8.8 - -
CVE-2023-32679 2023-05-19 2026-06-17 7.2 - -
CVE-2023-2817 2023-05-26 2026-06-17 5.4 - -
CVE-2023-33197 2023-05-26 2026-06-17 5.5 - -
CVE-2023-33194 2023-05-26 2026-06-17 3.7 - -
CVE-2023-33196 2023-05-26 2026-06-17 5.5 - -
CVE-2023-33195 2023-05-27 2026-06-17 5.0 - -
CVE-2023-30179 2023-06-13 2026-06-17 7.2 - -
CVE-2023-33495 2023-06-20 2026-06-17 6.1 - -
CVE-2023-40035 2023-08-23 2026-06-17 7.2 - -
CVE-2023-41892 2023-09-13 2026-06-17 10.0 - -
CVE-2024-21622 2024-01-03 2026-06-17 5.4 - -
CVE-2023-36259 2024-01-30 2026-06-17 5.4 - -
CVE-2023-36260 2024-01-30 2026-06-17 7.5 - -
CVE-2024-37843 2024-06-25 2026-06-17 9.8 - -
CVE-2024-41800 2024-07-25 2026-06-17 4.8 - -
CVE-2024-45406 2024-09-09 2026-06-17 5.5 - -
CVE-2024-52293 2024-11-13 2026-06-17 7.2 - -
CVE-2024-52291 2024-11-13 2026-06-17 8.4 - -
CVE-2024-52292 2024-11-13 2026-06-17 7.7 - -
CVE-2024-56145 2024-12-18 2026-06-17 9.8 - -
CVE-2025-23209 2025-01-18 2026-06-17 8.0 - -
CVE-2025-32432 2025-04-25 2026-06-17 10.0 - -
CVE-2025-46731 2025-05-05 2026-06-17 7.2 - -
CVE-2025-35939 2025-05-07 2026-06-17 5.3 - -
CVE-2025-54417 2025-08-09 2026-06-17 8.8 - -
CVE-2025-57811 2025-08-25 2026-06-17 7.2 - -
CVE-2025-68436 2026-01-05 2026-06-17 6.5 - -
CVE-2025-68437 2026-01-05 2026-06-17 6.8 - -
CVE-2025-68454 2026-01-05 2026-06-17 8.8 - -
CVE-2025-68455 2026-01-05 2026-06-17 7.2 - -
CVE-2025-68456 2026-01-05 2026-06-17 9.1 - -
CVE-2026-25482 2026-02-03 2026-06-17 4.8 - -
CVE-2026-25483 2026-02-03 2026-06-17 5.4 - -
CVE-2026-25484 2026-02-03 2026-06-17 4.8 - -
CVE-2026-25485 2026-02-03 2026-06-17 4.8 - -
CVE-2026-25486 2026-02-03 2026-06-17 4.8 - -
CVE-2026-25487 2026-02-03 2026-06-17 4.8 - -
CVE-2026-25488 2026-02-03 2026-06-17 4.8 - -
CVE-2026-25489 2026-02-03 2026-06-17 4.8 - -
CVE-2026-25490 2026-02-03 2026-06-17 4.8 - -
CVE-2026-25522 2026-02-03 2026-06-17 4.8 - -
CVE-2026-25491 2026-02-09 2026-06-17 4.8 - -
CVE-2026-25492 2026-02-09 2026-06-17 6.5 - -
CVE-2026-25493 2026-02-09 2026-06-17 6.5 - -
CVE-2026-25494 2026-02-09 2026-06-17 6.5 - -
CVE-2026-25495 2026-02-09 2026-06-17 8.8 - -
CVE-2026-25496 2026-02-09 2026-06-17 4.8 - -
CVE-2026-25497 2026-02-09 2026-06-17 8.8 - -
CVE-2026-25498 2026-02-09 2026-06-17 7.2 - -
CVE-2026-27126 2026-02-24 2026-06-17 4.8 - -
CVE-2026-27127 2026-02-24 2026-06-17 6.3 - -
CVE-2026-27128 2026-02-24 2026-06-17 4.8 - -
CVE-2026-27129 2026-02-24 2026-06-17 6.5 - -
CVE-2026-28695 2026-03-04 2026-06-17 7.2 - -
CVE-2026-28696 2026-03-04 2026-06-17 7.5 - -
CVE-2026-28697 2026-03-04 2026-06-17 9.1 - -
CVE-2026-28781 2026-03-04 2026-06-17 6.5 - -
CVE-2026-28782 2026-03-04 2026-06-17 4.3 - -
CVE-2026-28783 2026-03-04 2026-06-17 9.1 - -
CVE-2026-28784 2026-03-04 2026-06-17 7.2 - -
CVE-2026-29069 2026-03-04 2026-06-17 5.3 - -
CVE-2026-29113 2026-03-10 2026-09-02 4.3 - -
CVE-2026-29172 2026-03-10 2026-06-17 8.8 - -
CVE-2026-29173 2026-03-10 2026-06-17 4.8 - -
CVE-2026-29174 2026-03-10 2026-06-17 8.8 - -
CVE-2026-29175 2026-03-10 2026-06-17 5.4 - -
CVE-2026-29176 2026-03-10 2026-06-17 4.8 - -
CVE-2026-29177 2026-03-10 2026-06-17 5.4 - -
CVE-2026-31857 2026-03-11 2026-06-17 8.8 - -
CVE-2026-31858 2026-03-11 2026-06-17 8.8 - -
CVE-2026-31859 2026-03-11 2026-06-17 6.1 - -
CVE-2026-31867 2026-03-11 2026-06-17 4.8 - -
CVE-2026-32262 2026-03-16 2026-06-17 4.3 - -
CVE-2026-32263 2026-03-16 2026-06-17 7.2 - -
CVE-2026-32264 2026-03-16 2026-06-17 7.2 - -
CVE-2026-32267 2026-03-16 2026-06-17 9.8 - -
CVE-2026-33051 2026-03-20 2026-06-17 5.4 - -
CVE-2026-33157 2026-03-24 2026-06-17 7.2 - -
CVE-2026-33158 2026-03-24 2026-06-17 6.5 - -
CVE-2026-33159 2026-03-24 2026-06-17 6.5 - -
CVE-2026-33160 2026-03-24 2026-06-17 5.3 - -
CVE-2026-33161 2026-03-24 2026-06-17 4.3 - -
CVE-2026-33162 2026-03-24 2026-06-17 6.5 - -
CVE-2026-79989 2026-09-02 2026-09-09 - - -
CVE-2026-79990 2026-09-02 2026-09-03 - - -
CVE-2026-79991 2026-09-02 2026-09-03 - - -
CVE-2026-55795 2026-09-14 2026-09-14 - - -

How SecUtils Normalizes Vendor Data

SecUtils aggregates National Vulnerability Database (NVD) and MITRE records for craftcms by normalizing vendor identifiers across diverse data sources, mapping vendor names to their associated product lines, and collecting all known vulnerabilities under a unified vendor context. For every CVE associated with craftcms's products, we extract and structure Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) categories, CVSS severity metrics, and reference links to enable rapid vulnerability identification and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and vendor vulnerability tracking.