CVE-2026-28697: Craft CMS
Critical severity, CVSS 9.1. EPSS: 1.1% chance of exploitation in the next 30 days.
Craft is a content management system (CMS). Prior to 4.17.0-beta.1 and 5.9.0-beta.1, an authenticated administrator can achieve Remote Code Execution (RCE) by injecting a Server-Side Template Injection (SSTI) payload into Twig template fields (e.g., Email Templates). By calling the craft.app.fs.write() method, an attacker can write a malicious PHP script to a web-accessible directory and subsequently access it via the browser to execute arbitrary system commands. This vulnerability is fixed in 4.17.0-beta.1 and 5.9.0-beta.1.
Affected products
- Craft CMS Craft CMS: after 4.0.0, before 4.17.0 (fixed in 4.17.0); after 5.0.0, before 5.9.0 (fixed in 5.9.0); version 4.0.0 only; version 5.0.0 only
Published 2026-03-04. Last modified 2026-06-17.