Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read), these fields are gated only on the elements.drafts:read / elements.revisions:read scopes, and their resolver returns a raw User element whose email, username, fullName, and addresses fields have no per-field authorization. A client holding only the drafts or revisions scope — including an unauthenticated client when the operator has enabled the public GraphQL schema with those scopes — can therefore harvest the email addresses, usernames, full names, and postal addresses of all draft/revision creators (typically site editors and administrators). The issue is fixed in 5.11.0. Join the discussion | CVE Database V5 | 09/16/2026, 21:46:59 UTC Added: 09/16/2026, 22:02:48 UTC |
0 Craft CMS versions 5.10.0 through 5.10.12 contain a vulnerability allowing authenticated low-privilege control panel users with edit rights on a single element type to execute arbitrary PHP code via server-side template injection. This occurs due to an incomplete fix for a previous vulnerability, where the unsandboxed sink in the code remained exploitable. The issue is resolved in version 5.10.13. Join the discussion | CVE Database V5 | 09/16/2026, 21:46:58 UTC Added: 09/16/2026, 22:02:46 UTC |
0 Craft CMS versions 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 contain a vulnerability where an authenticated non-administrator user can execute arbitrary operating system commands. This occurs due to improper binding of HMAC signatures to their purpose, allowing an attacker to reuse a signed cookie in a redirect parameter that is rendered as an unsandboxed Twig template. The issue requires password authentication without 2FA and availability of PHP system(). The vulnerability is fixed in versions 4.18.6 and 5.10.13. Join the discussion | CVE Database V5 | 09/16/2026, 21:46:57 UTC Added: 09/16/2026, 22:02:46 UTC |
Craft CMS versions 5.0.0 through 5.10.12 have a vulnerability where a database connection failure causes the system to treat the site as uninstalled. This exposes installer actions to unauthenticated users who have a valid guest session and CSRF token from before the outage. Attackers can exploit this to disclose sensitive environment variables and secrets such as security keys and database credentials. The vulnerability requires an independent database outage and is fixed in version 5.10.13. Join the discussion | CVE Database V5 | 09/16/2026, 21:46:57 UTC Added: 09/16/2026, 22:02:46 UTC |
0 Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inject malicious JavaScript through editable fields that executes in authenticated Control Panel sessions of higher-privileged users viewing element indexes. Join the discussion | CVE Database V5 | 09/16/2026, 21:46:56 UTC Added: 09/16/2026, 22:02:46 UTC |
0 Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without savePeerEntries) opens another author's entry in read-only mode, Craft unconditionally grants that session a `manageNestedElements::<ownerId>::field:<handle>` authorization flag for the entry's Matrix/Address fields. Unlike the corresponding delete endpoint, actions/nested-elements/reorder trusts this session flag alone and never rechecks the caller's save permission for the owner element. As a result, a view-only user can POST to actions/nested-elements/reorder using the ownerElementType, ownerId, ownerSiteId, attribute, elementIds, and offset parameters present in the read-only page source and rewrite the sort order of Matrix blocks or Addresses belonging to content they are explicitly denied save access to. Join the discussion | CVE Database V5 | 09/16/2026, 21:46:55 UTC Added: 09/16/2026, 22:02:46 UTC |
0 Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (the users/activate-user action). While the action requires the administrateUsers permission, it does not call requireAdmin() when the targeted user is an administrator, unlike the mirror action actionDeactivateUser. As a result, an authenticated control panel user who is not an administrator but holds the administrateUsers permission can activate a pending or deliberately deactivated administrator account, which can lead to permission escalation when combined with resetting that account's password. The issue is fixed in Craft CMS 5.10.12. Join the discussion | CVE Database V5 | 09/08/2026, 15:14:01 UTC Added: 09/08/2026, 15:29:03 UTC |
0 Craft CMS versions before 5.10.12 fail to properly cleanse string-typed field-layout elements, allowing authenticated control-panel users to inject Yii2 behavior attachments and event handlers. Attackers can post field-layout tab elements as JSON strings to bypass cleanse validation, then trigger arbitrary object instantiation and code execution through Craft::createObject(). Join the discussion | CVE Database V5 | 09/08/2026, 15:14:00 UTC Added: 09/08/2026, 15:29:03 UTC |
0 Craft CMS versions before 5.10.8 contain a stored cross-site scripting vulnerability in the control panel where draft names are rendered without HTML encoding in element chips and cards. A low-privilege user who can create element drafts can inject malicious JavaScript that executes in the browser of any higher-privileged user viewing the affected element, allowing account creation and other authenticated actions. Join the discussion | CVE Database V5 | 08/12/2026, 19:07:36 UTC Added: 08/12/2026, 19:27:03 UTC |
0 Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can permanently modify that group's category structure — reordering and re-parenting categories — via the structures/move-element action. The structureEditable flag is computed from the view permission rather than the save permission, and the StructuresController authorizes the mutating action on that read-time session grant without a save re-check. Because a category's URI is derived from its position in the structure, moving a category changes its URL and those of its descendants and can corrupt navigation menus built from the category taxonomy. The issue is fixed in 5.10.6. Join the discussion | CVE Database V5 | 08/11/2026, 12:17:19 UTC Added: 08/11/2026, 12:42:11 UTC |
Showing 1 to 10 of 229 results