CMS
craftcms/cms
Build bespoke content experiences with Craft.
#cms#craftcms#yii2#php#twig#php7#content-management#craft3#php8#graphql#craft4
スコア
80
/ 100
Star
3,569
Fork
692
Open Issue
465
サイズ
980MB
言語
PHP ★
最終push
0 日前
Docker
—
採点内訳
過去CVE 19件 (やや多い)
✓直近 push: 0 日前
✓得意言語 (PHP)
✓オープンissue 465件
✓超大規模 (1.0GB)
—Docker 未対応
—1k–10k: 初心者ベスト (★3,569)
✓※ 各項目の重みは「採点ルール」を参照。合計は 0 で底打ち。
過去の SecurityAdvisory (20 件)
- Potential authenticated Remote Code Execution via malicious attached Behavior
- Missing Authorization in GraphQL Address Resolver Allows Cross-Scope PII Disclosure
- Missing Volume Permission Check in AssetsController::actionShowInFolder Allows Information Disclosure
- Host header injection leads to SSRF via resource-js endpoint
- Server-Side Request Forgery (SSRF) in Craft CMS with Asset Uploads Mutations
- Missing Authorization Check on User Group Removal via save-permissions Action
- Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section permissions
- Potential authenticated Remote Code Execution via malicious attached Behavior
- Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata
- Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users
- Anonymous "generate transform" calls for assets can expose private assets via transform URL
- Low-privilege users could read private asset contents when editing an asset (IDOR)
- Unauthenticated users could execute project configuration sync operations that should be restricted trusted users
- Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken()
- Incomplete fix for GHSA-7jx7-3846-m7w7: Behavior injection RCE ElementIndexesController and FieldsController
- Incomplete fix for GHSA-7jx7-3846-m7w7: Behavior injection RCE via EntryTypesController
- Path Traversal in AssetsController
- Stored XSS in Revision Context Menu
- ElementSearchController Blind SQL Injection (Bypass of GHSA-2453-mppf-46cj)
- RCE vulnerability via relational conditionals in the control panel