Craft CMS — Cyber Threats, Attacks & Incidents

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
April 12, 2026
Last Seen
July 9, 2026

Craft CMS is a technology platform tracked across 3 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed April 12, 2026; most recent activity July 9, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Second alert from ACSC in two months shows unpatched CMS bugs still exploited — Itnews.Au · July 9, 2026
  • nvd.nist.gov /vuln/detail/CVE-2026-55794 — nvd.nist.gov · July 7, 2026
  • CVE-2026-55794: Craft CMS: Potential authenticated Remote Code Execution via referrer redirect — Advisories.Gitlab · July 7, 2026
  • CVE-2026-31857 — nvd.nist.gov · April 12, 2026
  • Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2026-31857) — Acunetix · April 12, 2026

CVSS v3.1 Breakdown