← Back to browse · API

CVE-2023-41892

Severity
CRITICAL
CVSS
10.0
EPSS
0.92555
Risk score
72.39
CISA KEV
No
PoC
No
Published
2023-09-13
Modified
2025-02-13
First seen
2026-08-07
Aliases
EUVD-2023-2422, GHSA-4W8R-3XRW-V25G
Products
statamic:CMS 4.0.0-RC1, ≤ 4.4.14
Sources
euvd EUVD-2023-2422

Description

Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.

References