SQL Injection Vulnerability in Craft Platform by Craft CMS
CVE-2026-25495
What is CVE-2026-25495?
The Craft platform is exposed to SQL injection via the element-indexes/get-elements endpoint due to improper input sanitization in versions 4.0.0-RC1 to 4.16.17 and 5.0.0-RC1 to 5.8.21. Attackers with Control Panel access can exploit this flaw by manipulating the criteria[orderBy] parameter in the JSON body, allowing them to inject arbitrary SQL commands into the ORDER BY clause. This vulnerability is addressed in newer versions, specifically 4.16.18 and 5.8.22.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
cms >= 5.0.0-RC1, < 5.8.22 < 5.0.0-RC1, 5.8.22
cms >= 4.0.0-RC1, < 4.16.18 < 4.0.0-RC1, 4.16.18
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
