Frequency
2
occurrences
First Seen
July 7, 2026
Last Seen
July 7, 2026
Exploited in Wild
—
Ransomware Use
—
Public Exploits
—
Attack Vector
—
Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
Craft CMS versions 5.9.0 and above prior to 5.10.0 are vulnerable to authenticated remote code execution (RCE) due to a flaw in how the control panel processes the HTTP Referrer header. Users with edit permissions can execute unsandboxed Twig code when saving entries, as the signed redirect URL is c...
Public Exploits
Checking GitHub for proof-of-concept code…