CVE-2019-15929: Craft CMS
Critical severity, CVSS 9.8. EPSS: 1.8% chance of exploitation in the next 30 days.
In Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a brute force attempt on them.
Affected products
- Craft CMS Craft CMS: up to and including 3.1.7
Published 2019-10-24. Last modified 2026-06-17.