Skip to content

CVE-2026-21720

CVE

Threat entity extracted from intelligence sources

Frequency
1
occurrences
First Seen
April 12, 2026
Last Seen
April 12, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A Remote Code Execution vulnerability (CVE-2026-31857) has been identified in Craft CMS versions prior to 5.9.9 and 4.17.4. The flaw exists in the BaseElementSelectConditionRule::getElementIds() method, which improperly processes user-controlled input through an unsandboxed Twig rendering function,...

Public Exploits

Checking GitHub for proof-of-concept code…