Filtered by vendor Markhuot Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2026-31317 1 Markhuot 1 Craftql 2026-04-17 N/A
Craftql v1.3.7 and before is vulnerable to Server-Side Request Forgery (SSRF) which allows an attacker to execute arbitrary code via the vendor/markhuot/craftql/src/Listeners/GetAssetsFieldSchema.php file