craftcms/cms Security Advisories for 5.0.0-alpha.12 (3)
- 
                        [MEDIUM] Craft CMS stores arbitrary content provided by unauthenticated users in session filesPKSA-ht16-h36v-hxc7 CVE-2025-35939 GHSA-7vrx-9684-xrf2 Affected version: <4.15.3|>=5.0.0-alpha.1,<5.7.5 Reported by: 
 GitHub
- 
                        [HIGH] Craft CMS Arbitrary System File ReadPKSA-jkbm-w624-yb7q CVE-2024-52292 GHSA-cw6g-qmjq-6w2w Affected version: >=3.5.13,<=4.12.6.1|>=5.0.0-alpha.1,<=5.4.7.1 Reported by: 
 GitHub
- 
                        [MEDIUM] Craft CMS vulnerable to stored XSS in breadcrumb list and title fieldsPKSA-8qn2-9hhy-cmx1 CVE-2024-45406 GHSA-28h4-788g-rh42 Affected version: >=5.0.0,<5.1.2 Reported by: 
 GitHub