Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-31857 — CraftCMS has an RCE vulnerability via relational conditionals in the control panel | Kitploit
Tools/GitHubGitHub/0asylum/cve-2026-31857
Vulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingCommand and ControlRemote Access Tool
GitHub0asylum/cve-2026-31857

CVE-2026-31857

CraftCMS has an RCE vulnerability via relational conditionals in the control panel

View Repository
1 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-31857: Craft CMS control panel RCE

CVE-2026-31857 is a remote code execution issue in Craft CMS relational condition rules. BaseElementSelectConditionRule::getElementIds() renders user-controlled input as an unsandboxed Twig template. An authenticated Control Panel user can submit a crafted condition through an element listing endpoint and execute commands on the server. Administrator privileges are not required.

Craft CMS 4.0.0-beta.1 through 4.17.3 and 5.0.0-RC1 through 5.9.8 are affected. This PoC uses the Craft 5 element-index request shape.

Usage

Python 3 with only the standard library is required. Supply the base URL and a Control Panel username; the script prompts for the password:

python3 poc.py https://craft.example editor

Enter commands at cmd>, or enter exit to quit. The current working directory persists between commands. To launch a long-running command, end it with &; its input and output are detached from the HTTP request and its output is discarded. Command output returned through the response header is limited to the last 1200 bytes.

References

  • CVE Details: CVE-2026-31857
  • Craft CMS security advisory GHSA-fp5j-j7j4-mcxc
Download Tool