CVE-2024-37899 is a vulnerability tracked across 1 threat cluster and 1 intelligence report mention on ThreatCluster. First observed April 12, 2026; most recent activity April 12, 2026.
A Remote Code Execution vulnerability (CVE-2026-31857) has been identified in Craft CMS versions prior to 5.9.9 and 4.17.4. The flaw exists in the BaseElementSelectConditionRule::getElementIds() method, which improperly…