CVE Explorer
CVE-2026-28784
Craft is a content management system (CMS). Prior to 5.8.22 and 4.16.18, it is possible to craft a malicious payload using the Twig map filter in text fields that accept Twig input under Settings in the Craft control panel or using the System Messages utility, which could lead to a RCE. For this to work, you must have administrator access to the Craft Control Panel, and allowAdminChanges must be enabled for this to work, which is against our recommendations for any non-dev environment. Alternati
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"cms","vendor":"craftcms","versions":[{"status":"affected","version":">= 5.0.0-RC1, < 5.9.0-beta.1"},{"status":"affected","version":">= 4.0.0-RC1, < 4.17.0-beta.1"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:1b0bd2bb55d96024cc95c6bb8b5c8ad70ce236548443306558207f525f4d5420 · sha256:409eba594ae3da6d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.6,"baseSeverity":"HIGH","privilegesRequired":"HIGH","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:1b0bd2bb55d96024cc95c6bb8b5c8ad70ce236548443306558207f525f4d5420 · sha256:409eba594ae3da6d… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-1336","description":"CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:1b0bd2bb55d96024cc95c6bb8b5c8ad70ce236548443306558207f525f4d5420 · sha256:409eba594ae3da6d… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://craftcms.com/knowledge-base/securing-craft#set-allowAdminChanges-to-false-in-production","tags":["x_refsource_MISC"],"url":"https://craftcms.com/knowledge-base/securing-craft#set-allowAdminChanges-to-false-in-production"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1b0bd2bb55d96024cc95c6bb8b5c8ad70ce236548443306558207f525f4d5420 · sha256:409eba594ae3da6d… · /containers/cna/references/2
{"name":"https://github.com/craftcms/cms/pull/18208","tags":["x_refsource_MISC"],"url":"https://github.com/craftcms/cms/pull/18208"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1b0bd2bb55d96024cc95c6bb8b5c8ad70ce236548443306558207f525f4d5420 · sha256:409eba594ae3da6d… · /containers/cna/references/1
{"name":"https://github.com/craftcms/cms/security/advisories/GHSA-qc86-q28f-ggww","tags":["x_refsource_CONFIRM"],"url":"https://github.com/craftcms/cms/security/advisories/GHSA-qc86-q28f-ggww"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:1b0bd2bb55d96024cc95c6bb8b5c8ad70ce236548443306558207f525f4d5420 · sha256:409eba594ae3da6d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.