Логотип exploitDog
bind:CVE-2025-46731
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-46731

Количество 2

Количество 2

nvd логотип

CVE-2025-46731

9 месяцев назад

Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13 or 5.6.15 to mitigate the issue.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-7c58-g782-9j38

9 месяцев назад

Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-46731

Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13 or 5.6.15 to mitigate the issue.

CVSS3: 7.2
0%
Низкий
9 месяцев назад
github логотип
GHSA-7c58-g782-9j38

Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI

0%
Низкий
9 месяцев назад

Уязвимостей на страницу