← Vulnerability feed

Vulnerability record · CVE-2024-37843 · published 25 June 2024

CVE-2024-37843: Craft CMS SQL injection via GraphQL API endpoint

Craftcms · Craft Cms

Craft CMS up to v3.7.31 contains a SQL injection flaw reachable through its GraphQL API endpoint. The CVSS vector indicates the attack is network-reachable with no authentication or user interaction, and the impact spans confidentiality, integrity and availability. Because the endpoint is public-facing in typical deployments, this is a serious pre-auth injection risk.

9.8 CVSS 3.1 Critical EPSS 53% · top 1.1% CWE-89 · SQL injection
9.8CVSS 3.1 base score
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, combined with a very high EPSS percentile, makes this a top remediation priority.

What it is

Craft CMS up to v3.7.31 contains a SQL injection flaw reachable through its GraphQL API endpoint. The CVSS vector indicates the attack is network-reachable with no authentication or user interaction, and the impact spans confidentiality, integrity and availability. Because the endpoint is public-facing in typical deployments, this is a serious pre-auth injection risk.

Impact

An attacker can inject arbitrary SQL through the GraphQL API, potentially reading, modifying or deleting database contents and disrupting the application. With no privileges required, the exposure is broad.

Attack surface

Reached over the network via the GraphQL API endpoint; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are needed. The description does not specify which GraphQL query or field is vulnerable.

Exploitation

Not listed in CISA KEV and no ransomware usage documented. EPSS is 0.53242 (98.9th percentile), indicating a high modeled likelihood of exploitation, but the only references are tagged as broken links, so no confirmed public exploit is documented in this record.

What to do

  • Upgrade Craft CMS to a version above 3.7.31 as soon as a fixed release is available; confirm the patched version from the vendor.
  • If immediate upgrade is not possible, restrict or disable the GraphQL API endpoint and limit it to trusted networks or authenticated users.
  • Apply input validation and parameterized queries for any custom GraphQL resolvers that touch the database.
  • Monitor and rate-limit GraphQL requests, and block requests containing obvious SQL injection patterns.
  • Review database accounts used by Craft CMS and apply least privilege to limit the impact of a successful injection.

Detection

  • Inspect web and GraphQL access logs for anomalous query strings, SQL keywords, or unusual GraphQL operations targeting the API endpoint.
  • Enable database query logging and look for unexpected or malformed SQL generated from the application.
  • Alert on high volumes of GraphQL requests from single sources or requests returning database error messages.
  • Correlate Craft CMS application logs with database errors to identify injection attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-37843 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32432Craft CMS unauthenticated remote code execution via code injectionCraft CMS versions 3.0.0-RC1 through 3.9.14, 4.0.0-RC1 through 4.14.14, and 5.0.0-RC1 through 5.6.16 contain a code injection flaw enabling remote co…KEVEPSS 100%analysed9.3CVE-2024-56145Craft CMS code injection via register_argc_argv leads to RCECraft CMS contains a code injection flaw (CWE-94) that allows remote code execution when the PHP setting register_argc_argv is enabled. The vendor de…KEVEPSS 97%analysed8.1CVE-2025-23209Craft CMS code injection RCE with compromised security keyCraft CMS 4 and 5 contain a code injection flaw (CWE-94) that allows remote code execution when the installation's security key has already been comp…KEVEPSS 22%analysed6.9CVE-2025-35939Craft CMS unauthenticated session file write enables PHP code injectionCraft CMS stores unsanitized client-supplied return URL values in server-side session files for unauthenticated users. Because the session file path …KEVEPSS 1.3%analysed9.8CVE-2023-41892Craft CMS code injection enables unauthenticated remote code executionCraft CMS versions before 4.4.15 contain a code injection flaw (CWE-94) that allows remote code execution. The vendor describes it as a high-impact, …EPSS 94%analysed9.8CVE-2021-27903Craftcms craft cms missing authorization vulnerabilityAn issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did n…EPSS 2.8%9.8CVE-2020-9757SEOmatic for Craft CMS template injection leads to RCEThe SEOmatic component for Craft CMS before 3.3.0 is vulnerable to server-side template injection through malformed data sent to the metacontainers c…EPSS 73%analysed9.8CVE-2019-15929Craftcms craft cms weak password recovery vulnerabilityIn Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a …EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2024-37843), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.