CVE-2026-25495Disclosure(craftcms / craft_cms)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/get-elements endpoint is vulnerable to SQL Injection via the criteria[orderBy] parameter (JSON body). The application fails to sanitize this input before using it in the database query. An attacker with Control Panel access can inject arbitrary SQL into the ORDER BY clause by omitting viewState[order] (or setting both to the same payload). This issue is patched in versions 4.16.18 and 5.8.22.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • craft_cms

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
craft_cms

2 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-09: 3Technical Details · 2026-02-09: 302-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-25495 Craft is a platform for creating digital experiences. In Craft versions 4.0.0-RC1 through 4.16.17 and 5.0.0-RC1 through 5.8.21, the element-indexes/get-elements endpo… https://www.cve.org/CVERecord?id=CVE-2026-25495

    Post summary

    Disclosed CVE‑2026‑25495 impacts Craft platform versions 4.x and 5.x, affecting the element‑indexes/get‑elements endpoint.

    00010122
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25495: Craft CMS: The Art of SQL Injection via Mass Assignment A high-severity SQL injection vulnerability in Craft CMS allows authenticated Control Panel users to execute arbitrary SQL commands. The flaw stems from a mass assignment vulnerab... https://cvereports.com/reports/CVE-2026-25495

    Post summary

    The text discloses a high‑severity SQL injection vulnerability in Craft CMS that permits authenticated Control Panel users to execute arbitrary SQL commands through a mass‑assignment flaw, but it provides no PoC, exploit code, or patch information.

    0000058
    27 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25495 SQL Injection in Craft CMS Control Panel via Unsanitized Order By Parameter https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25495

    Post summary

    The text announces a new SQL injection vulnerability in Craft CMS's Control Panel, triggered by an unsanitized order‑by parameter, but does not provide PoC, exploit code, or active exploitation evidence.

    0000038
    4.0K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
Appcraftcmscraft_cms---
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms4.0.0--
Appcraftcmscraft_cms5.0.0--
Appcraftcmscraft_cms5.0.0--

Explore more