CyberzSOC

Applicability
← Back to CVE-2024-56145

CVE-2024-56145

In CISA KEV Craft CMS

Every applicability statement published about this vulnerability, kept as each source wrote it rather than merged into one verdict. Where sources disagree, both positions are shown.

Does it affect your version?

A statement that names no version covers the whole product, which is not the same as your version falling inside a range. Orderings marked best effort come from schemes with no published comparison algorithm; exact ones follow a published specification.

What each source says

OSV.dev (incl. GHSA)
precedence 80 · revised 2026-08-12
7 affected 7 fixed
CVE List v5 (CNA container)
precedence 60 · revised 2025-10-21
3 affected

Precedence decides which claim wins when two sources describe the same product over the same version range. It is a property of the source, not of the claim, and changing it re-ranks the data without re-reading a single document.

Statements (17)

Product Status Versions Remediation Source
craftcms/cms affected >= 5.0.0-RC1, < 5.5.2 vendor fix → 5.5.2 osv GHSA-2p6p-9rc9-62j9
craftcms/cms affected >= 4.0.0-RC1, < 4.13.2 vendor fix → 4.13.2 osv GHSA-2p6p-9rc9-62j9
craftcms/cms affected >= 3.0.0, < 3.9.14 vendor fix → 3.9.14 osv GHSA-2p6p-9rc9-62j9
https://github.com/craftcms/cms affected >= 18263261a5a70f0f84d78db6c4449b6fe304224e, < 31c8d3e485c8f39ae438cee83805edb9a8123d3e vendor fix → 31c8d3e485c8f39ae438cee83805edb9a8123d3e osv
https://github.com/craftcms/cms affected >= 982efcd14d7e93a1a54f0905b61f242de6b53d8a, < b2515b0ce6ae02e8582ce5a10841cb933899cbe3 vendor fix → b2515b0ce6ae02e8582ce5a10841cb933899cbe3 osv
https://github.com/craftcms/cms affected >= f6a8fb685d44e387435825e3a96809eeda4973a6, < 43dc9cfba1d5ccb1cd0b5da4ff1ab6459db26811 vendor fix → 43dc9cfba1d5ccb1cd0b5da4ff1ab6459db26811 osv
https://github.com/craftcms/cms affected < 82e893fb794d30563da296bca31379c0df0079b3 vendor fix → 82e893fb794d30563da296bca31379c0df0079b3 osv
craftcms/cms fixed 5.5.2 vendor fix → 5.5.2 osv GHSA-2p6p-9rc9-62j9
craftcms/cms fixed 4.13.2 vendor fix → 4.13.2 osv GHSA-2p6p-9rc9-62j9
craftcms/cms fixed 3.9.14 vendor fix → 3.9.14 osv GHSA-2p6p-9rc9-62j9
https://github.com/craftcms/cms fixed 31c8d3e485c8f39ae438cee83805edb9a8123d3e vendor fix → 31c8d3e485c8f39ae438cee83805edb9a8123d3e osv
https://github.com/craftcms/cms fixed b2515b0ce6ae02e8582ce5a10841cb933899cbe3 vendor fix → b2515b0ce6ae02e8582ce5a10841cb933899cbe3 osv
https://github.com/craftcms/cms fixed 43dc9cfba1d5ccb1cd0b5da4ff1ab6459db26811 vendor fix → 43dc9cfba1d5ccb1cd0b5da4ff1ab6459db26811 osv
https://github.com/craftcms/cms fixed 82e893fb794d30563da296bca31379c0df0079b3 vendor fix → 82e893fb794d30563da296bca31379c0df0079b3 osv
craftcms/cms craftcms · cms affected >= 4.0.0-RC1, < 4.13.2 none available cve_cna
craftcms/cms craftcms · cms affected >= 5.0.0-RC1, < 5.5.2 none available cve_cna
craftcms/cms craftcms · cms affected >= 3.0.0, < 3.9.14 none available cve_cna

A claim with no version range is shown as written rather than expanded: a government catalog naming only a vendor and product is a real statement at zero granularity, and inventing bounds for it would put precision in the record that the source never offered.