Craft CMS is a technology platform tracked across 3 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed April 12, 2026; most recent activity July 9, 2026.
A Remote Code Execution vulnerability (CVE-2026-31857) has been identified in Craft CMS versions prior to 5.9.9 and 4.17.4. The flaw exists in the BaseElementSelectConditionRule::getElementIds() method, which improperly…
The Australian Cyber Security Centre (ACSC) has issued a second alert in two months regarding a large-scale hacking campaign exploiting unpatched vulnerabilities in content management systems (CMS). The campaign targets…
Craft CMS versions 5.9.0 and above prior to 5.10.0 are vulnerable to authenticated remote code execution (RCE) due to a flaw in how the control panel processes the HTTP Referrer header. Users with edit permissions can…