PT-2026-24686 · Craft Cms+2 · Cms+2

·

CVE-2026-31858

·

Published

2026-03-11

·

Updated

2026-03-12

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Craft versions prior to 5.9.9
Description Craft is a content management system (CMS). The ElementSearchController::actionSearch() API endpoint lacks the unset() protection that was added to ElementIndexesController. This results in a SQL injection issue, specifically affecting parameters like criteria[orderBy]. Any authenticated control panel user can inject arbitrary SQL through criteria[where], criteria[orderBy], or other query properties. This allows for the extraction of the full database contents via boolean-based blind injection.
Recommendations Update to version 5.9.9 to resolve the issue.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-31858
GHSA-G7J6-FMWX-7VP8

Affected Products

Cms
Craft Cms
Craftcms/Cms