Known vulnerabilities in Pixel & Tonic, Inc. Craft CMS 3.9.0

Website: https://craftcms.com/
Total Security Bulletins: 7

Security bulletins (7)

Secuity bulletin Severity Status Published
SB2026021833: Multiple vulnerabilities in Craft CMS Medium
Patched Public exploit
18.02.2026
SB2026010560: Multiple vulnerabilities in Craft CMS High
Patched Public exploit
05.01.2026
SB2025042834: Remote code execution in Craft CMS Critical
Patched Exploited
28.04.2025
SB2024030712: Server-side template injection in Craft CMS Medium
Patched
07.03.2024
SB2024010422: Privilege escalation in Craft CMS High
Patched
04.01.2024
SB2024010314: Privilege escalation in Craft CMS Medium
Patched
03.01.2024
SB2023101838: Remote code execution in Craft CMS High
Patched
18.10.2023