PT-2026-22997 · Craft Cms · Craft Cms
Rajchowdhury240
+1
·
Published
2026-03-03
·
Updated
2026-03-05
·
CVE-2026-28784
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Craft versions prior to 5.8.22
Craft versions prior to 4.16.18
Description
Craft, a content management system (CMS), is susceptible to Remote Code Execution (RCE) through a Server-Side Template Injection (SSTI) issue. A malicious payload can be crafted using the Twig
map filter within text fields that accept Twig input. This is possible in the Settings section of the Craft control panel or through the System Messages utility. To successfully exploit this, an attacker must have administrator access to the Craft Control Panel with the allowAdminChanges setting enabled, or a non-administrator account with allowAdminChanges disabled but access to the System Messages utility. The allowAdminChanges setting controls whether non-administrator users can modify settings within the Craft control panel.Recommendations
Craft versions prior to 5.8.22 should be updated to version 5.8.22.
Craft versions prior to 4.16.18 should be updated to version 4.16.18.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Craft Cms