| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
The security of Craft CMS, Craft Commerce, Craft Cloud, and all Pixel & Tonic plugins is of the utmost importance to us, our community, and our customers.
We strive to ensure the integrity of our software and infrastructure and to maintain processes to address all security issues in a timely manner while minimizing customer exposure.
Craft CMS is a self-hosted PHP web application. It is important for developers, administrators, and customers to realize it is not a “shrink-wrapped” solution and that every site is 100% unique and custom-built. Because of this, we do not have access to the infrastructure a self-hosted Craft is installed on, or even knowledge of where it is hosted.
From a security perspective, we are primarily concerned with issues arising from a fresh Craft installation, not with front-end site implementations or custom plugins or modules, unless they reveal a foundational issue that can be addressed in Craft’s native code across all installations.
The most secure version of Craft or Commerce is the latest one.
If you’re on a version of Craft or Commerce that is no longer being actively supported, you should update to a supported version.
Even if you are on a supported version, you should make sure you are running the latest release to ensure you have the latest security patches and bug fixes.
We triage, acknowledge, patch, and disclose any vulnerabilities in an industry-standard manner.
If you believe you have discovered a potential security vulnerability in our products, please report your findings to us as quickly as possible.
If you discover a security vulnerability, please review these guidelines before submitting a report. We take security seriously and do our best to resolve security issues as quickly and responsibly as possible.
While working to identify potential security vulnerabilities, we ask that you:
Once an issue has been reported, we will attempt to replicate it locally, on the latest release of Craft or Commerce. We might ask follow-up questions depending on the report.
If it is accepted, we will also publish a GitHub Security Advisory in the respective repository.
You can see an up-to-date list of known/fixed security issues in those repositories, and those should be considered the “source of truth” for security issues.
We may ask you to verify the fix during the collaboration process.
We wait 30 days after the Craft or Commerce release that has a fix before we make the security advisory public. This is to give customers time to update before any details are made public. We will also make an assigned CVE public at that time. We ask that reporters not disclose any information about the vulnerability until the 30-day window has passed and it is made public.
We are only interested in reports directly from the security researcher who discovered them.
We are interested in vulnerabilities that affect Craft or first-party Craft plugins, tested against your local installation of the software. You can install a local copy of Craft by following these installation instructions. Do not test against any Craft installation you don’t own, including craftcms.com.
We are interested in infrastructure-related vulnerabilities found on Craft Cloud.
Do not test against any Craft Cloud site you don’t own, and do not perform any tests that degrade Craft Cloud’s services.
Avoid reporting vulnerabilities that meet the following criteria:
We assign the broader severity categories of Critical, High, Moderate, and Low.
Critical: There is a very high chance of compromise for affected sites. Typically, these are through untrusted or unauthenticated users, and there may already be active exploits in the wild targeting vulnerable sites.
High: Poses a potential security threat to the underlying installation, although the flaw is usually difficult to exploit.
Moderate: Typically requires local network or user privileges to be exploited first, though not necessarily. The impact on business operations is slightly higher. The flaw is usually difficult to exploit.
Low: Most XSS vulnerabilities. Most denial of service vulnerabilities. They typically do not compromise the underlying data or system and don’t pose a risk of privilege escalation, arbitrary code execution, or data loss. Or if they do, but they have to go against our security recommendations to achieve it (e.g., allowAdminChanges enabled in production).
As a rule of thumb, here are some guidelines on when customers should update, depending on the severity level.
| Critical | High | Moderate | Low |
|---|---|---|---|
| Update ASAP | Update within 30 days | Update within 90 days (depending on your site’s needs) | Update at your convenience (depending on your site’s needs) |
| Back | FazBrowse Home | New Git URL |