
CVE-2026-44012 Craft CMS is a content management system (CMS). From 5.0.0-RC1 to before 5.9.18, AssetsController::actionShowInFolder() fetches an asset by ID and returns its filenam… https://www.cve.org/CVERecord?id=CVE-2026-44012
Post summary
The text provides a brief disclosure of CVE‑2026‑44012, noting its impact on Craft CMS from versions 5.0.0‑RC1 to 5.9.17 and describing the vulnerable function.
