
CVE-2026-25495 Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/get-elements endpo… https://www.cve.org/CVERecord?id=CVE-2026-25495
Post summary
Disclosed CVE‑2026‑25495 impacts Craft platform versions 4.x and 5.x, affecting the element‑indexes/get‑elements endpoint.


