CVE Explorer
CVE-2026-32261
Webhooks for Craft CMS plugin adds the ability to manage “webhooks” in Craft CMS, which will send GET or POST requests when certain events occur. From version 3.0.0 to before version 3.2.0, the Webhooks plugin renders user-supplied template content through Twig’s renderString() function without sandbox protection. This allows an authenticated user with access to the Craft control panel and permissions to access the Webhooks plugin to inject Twig template code that calls arbitrary PHP functions.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"webhooks","vendor":"craftcms","versions":[{"status":"affected","version":">= 3.0.0, < 3.2.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:79d29314853eea196c52a38689155dd23bd782f3edd198c6d562a6e21aca1954 · sha256:deb2f2628bb31d08… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.5,"baseSeverity":"HIGH","privilegesRequired":"HIGH","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:79d29314853eea196c52a38689155dd23bd782f3edd198c6d562a6e21aca1954 · sha256:deb2f2628bb31d08… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-1336","description":"CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:79d29314853eea196c52a38689155dd23bd782f3edd198c6d562a6e21aca1954 · sha256:deb2f2628bb31d08… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/craftcms/webhooks/commit/88344991a68b07145567c46dfd0ae3328c521f62","tags":["x_refsource_MISC"],"url":"https://github.com/craftcms/webhooks/commit/88344991a68b07145567c46dfd0ae3328c521f62"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:79d29314853eea196c52a38689155dd23bd782f3edd198c6d562a6e21aca1954 · sha256:deb2f2628bb31d08… · /containers/cna/references/1
{"name":"https://github.com/craftcms/webhooks/security/advisories/GHSA-8wg7-wm29-2rvg","tags":["x_refsource_CONFIRM"],"url":"https://github.com/craftcms/webhooks/security/advisories/GHSA-8wg7-wm29-2rvg"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:79d29314853eea196c52a38689155dd23bd782f3edd198c6d562a6e21aca1954 · sha256:deb2f2628bb31d08… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.