Critical RCE Vulnerabilities in Craft CMS Versions Before 5.10.12

Critical RCE Vulnerabilities in Craft CMS Versions Before 5.10.12

First seen 9 Sep 2026, 10:45 UTC www.vulncheck.com 70.5

Article Content

Browse articles
ThreatCluster

Two critical remote code execution (RCE) vulnerabilities have been identified in Craft CMS versions before 5.10.12. The first vulnerability, linked to behavior injection, affects Craft CMS 5.0.0 RC1 and earlier versions. The second vulnerability allows RCE via the element index, impacting all versions prior to 5.10.12. These vulnerabilities could allow attackers to execute arbitrary code on affected systems, potentially leading to full system compromise. Administrators are urged to prioritize patching these vulnerabilities due to their severity. Current status indicates that both vulnerabilities are disclosed but not yet confirmed to be actively exploited in the wild. No specific CVEs were mentioned in the articles. Organizations using Craft CMS are advised to update to version 5.10.12 or later to mitigate these risks.

Key Points: • Two critical RCE vulnerabilities found in Craft CMS before version 5.10.12. • Vulnerabilities allow arbitrary code execution, posing severe risks to affected systems. • Immediate patching is recommended to prevent potential exploitation.

Ask AI about this cluster

Timeline

2026-09-09
Vulnerabilities disclosed
Craft CMS vulnerabilities allowing RCE were publicly disclosed, affecting versions before 5.10.12.
VulnCheck
2026-09-09
Patch recommended
Administrators advised to upgrade to Craft CMS version 5.10.12 or later to mitigate risks.
VulnCheck