| Schwachstelle | 25.08.2026 00:27 | string-typed field-layout elements evade array-only cleanse, enabling behavior-injection RCE |
| Schwachstelle | 25.08.2026 00:27 | Missing admin-target guard in UsersController::actionActivateUser can lead to permission escalation |
| Schwachstelle | 25.08.2026 00:23 | Remote Code Execution by non-admin authenticated user |
| Incident | 24.08.2026 14:52 | Ransomware.live: Bihl (akira) |
| Incident | 24.08.2026 00:54 | Ransomware.live: resi.com (krybit) |
| Incident | 23.08.2026 21:26 | Ransomware.live: Westwing Group SE (coinbasecartel) |
| Incident | 23.08.2026 07:36 | Ransomware.live: MPA Pharma GmbH (metaencryptor) |
| Incident | 22.08.2026 22:54 | Ransomware.live: el-group (incransom) |
| Incident | 22.08.2026 08:00 | Ransomware.live: holzmarkt chemnitz (spacebears) |
| Incident | 21.08.2026 08:30 | Ransomware.live: dlp motive (thegentlemen) |
| Incident | 21.08.2026 08:27 | Cyberangriff auf die Arbeiterkammer Oberösterreich – Datenzugriff betrifft möglicherweise auch Salzburg |
| Incident | 20.08.2026 17:26 | Ransomware.live: Qualiflex Datacenter | HWZ-Studiengnge (fh-hwz.ch), myenb.ch, etc (payload) |
| Incident | 19.08.2026 12:28 | Ransomware.live: Estech (qilin) |
| Incident | 19.08.2026 11:00 | Ransomware.live: Smart Energies (qilin) |
| Schwachstelle | 18.08.2026 23:52 | Missing volume permission in AssetsController::actionMoveInfo leaks cross-volume asset count and total size |
| Schwachstelle | 18.08.2026 23:46 | Broken access control: a non-admin can move/publish entries into sections they cannot edit |
| Schwachstelle | 18.08.2026 23:43 | Stored XSS in site name rendered without escaping |
| Schwachstelle | 18.08.2026 23:41 | Authorization Bypass in assets/move-asset |
| Schwachstelle | 18.08.2026 23:37 | Public registration inherits admin flag from deactivated admin accounts via missing guard |
| Schwachstelle | 18.08.2026 23:34 | GQL entry mutation siteId bypasses schema site scope, enabling cross-site content read/write/delete |
| Schwachstelle | 18.08.2026 23:29 | actionDuplicate with deleteProvisionalDraft side-effect deletes peer drafts |
| Schwachstelle | 18.08.2026 23:25 | actionDeleteForSite propagates deletion to canonical element without independent authorization check |
| Schwachstelle | 18.08.2026 23:11 | PII disclosure with GraphQL native user relations |
| Schwachstelle | 18.08.2026 23:03 | Peer asset file overwrite via assets/replace-file late-discovered target skips permission check |
| Schwachstelle | 18.08.2026 23:02 | Non-admin with administrateUsers permissions can mint an admin password reset URL |
| Incident | 18.08.2026 13:19 | Ransomware.live: Logitech/ Streamlabs (shinyhunters) |
| Incident | 18.08.2026 10:26 | Ransomware.live: ssf-int.com ssf-ing.de (incransom) |
| Incident | 18.08.2026 03:55 | Ransomware.live: terra-petra.com (lockbit5) |
| Incident | 18.08.2026 03:21 | Ransomware.live: Scholle IPN / SIG (anubis) |
| Incident | 17.08.2026 16:22 | Ransomware.live: Planungsgruppe M+M AG (aurora) |
| Incident | 17.08.2026 00:00 | Senatsverwaltung Berlin |
| Schwachstelle | 16.08.2026 19:09 | RCE vulnerability via relational conditionals in the control panel · Advisory · craftcms/cms · GitHub |
| Schwachstelle | 16.08.2026 19:09 | Security Advisories · craftcms/commerce · GitHub |
| Incident | 16.08.2026 15:20 | Ransomware.live: Idex Group (medusalocker) |
| Incident | 16.08.2026 14:51 | Ransomware.live: tecosim.com (lockbit5) |
| Incident | 16.08.2026 12:30 | Ransomware.live: INVENSITY (qilin) |
| Incident | 16.08.2026 11:30 | Ransomware.live: Botek (qilin) |
| Incident | 16.08.2026 09:30 | Ransomware.live: DELTA WAYS (qilin) |
| Incident | 16.08.2026 09:30 | Ransomware.live: motorenmaier gmbh (qilin) |
| Incident | 15.08.2026 00:21 | Ransomware.live: Alpine Electronics Europe (Panzer) |
| Incident | 14.08.2026 08:33 | Ransomware.live: Lercher Werkzeugbau (qilin) |
| Incident | 14.08.2026 05:59 | Ransomware.live: Gfeller Treuhand und Verwaltungs (thegentlemen) |
| Incident | 14.08.2026 05:56 | Ransomware.live: Tempel (thegentlemen) |
| Incident | 13.08.2026 23:52 | Ransomware.live: Reminger (SilentRansomGroup) |
| Incident | 13.08.2026 04:35 | Phishing-Angriff auf Hotel-IT-Dienstleister Seekda betrifft Hotelgäste |
| Incident | 12.08.2026 15:32 | Ransomware.live: MAMMUT.COM (clop) |
| Incident | 12.08.2026 14:48 | Ransomware.live: SCHMITZ & NITTENWILM (majinahanashi) |
| Incident | 12.08.2026 14:47 | Ransomware.live: Camandona SA (majinahanashi) |
| Incident | 12.08.2026 12:46 | DDoS-Angriffe verursachen Ausfälle bei Threema |
| Incident | 12.08.2026 11:56 | Datenpanne bei Ceva Logistics betrifft Kunden mehrerer Unternehmen |
| Incident | 11.08.2026 16:43 | Cyberangriff legt IT-System der Stiftung Brandenburgischer Gedenkstätten lahm |
| Incident | 11.08.2026 14:30 | Ransomware.live: B&B Hydraulik (payload) |
| Incident | 11.08.2026 14:29 | Ransomware.live: Stücheli Architekten (payload) |
| Incident | 11.08.2026 07:06 | Transfermarkt.de nach DDoS-Attacke wieder online |
| Incident | 11.08.2026 05:51 | Cyberangriff auf Schmuckhändler Frey Wille |
| Incident | 11.08.2026 00:55 | Hackerangriff legte Rathaus der Stadtgemeinde Tulln lahm |
| Incident | 10.08.2026 18:57 | Ransomware.live: Statista GmbH (direwolf) |
| Incident | 10.08.2026 10:37 | Ransomware.live: Elixi International SA (spacebears) |
| Incident | 09.08.2026 16:35 | Framework meldet Datenpanne mit kompromittierten Kundendaten |
| Incident | 09.08.2026 15:28 | Cyberangriff auf Hugging Face durch autonom handelnde KI-Agenten |
| Incident | 09.08.2026 14:57 | Ransomware.live: pm-energy Die Solarexperten (qilin) |
| Incident | 09.08.2026 11:55 | Cyberangriff auf Rheinmetall |
| Incident | 08.08.2026 12:30 | Ransomware.live: Clausing (qilin) |
| Incident | 07.08.2026 13:42 | Ransomware.live: Hartfiel Automation (thegentlemen) |
| Incident | 07.08.2026 13:31 | Ransomware.live: EISNER ZT GMBH (qilin) |
| Incident | 07.08.2026 13:10 | Ransomwareangriff auf Südwestfalen-IT beeinträchtigte kommunale Verwaltungen |
| Incident | 07.08.2026 08:09 | Ransomware.live: INKA Group GmbH Co (thegentlemen) |
| Incident | 07.08.2026 08:04 | Ransomware.live: Nobema (thegentlemen) |
| Incident | 07.08.2026 04:35 | DDoS-Angriffe auf österreichisches Innenministerium und weitere Ministerien |
| Incident | 06.08.2026 14:22 | Ransomware.live: MITC AG (bravox) |
| Incident | 06.08.2026 11:51 | Ransomware.live: Pharma Test Apparatebau AG (akira) |
| Incident | 05.08.2026 21:28 | Ransomware.live: Festina Group (Panzer) |
| Incident | 05.08.2026 16:32 | Ransomware.live: STADLER Sensorik CNC-Technik (qilin) |
| Incident | 05.08.2026 14:36 | Cyberangriff auf SharePoint-Server des Kantons Graubünden |
| Incident | 05.08.2026 14:25 | Apple beantragt einstweilige Verfügung gegen OpenAI wegen angeblichen Datendiebstahls |
| Incident | 05.08.2026 09:38 | Urteile im Datenleck bei der Stuttgarter Staatsanwaltschaft gefällt |
| Incident | 04.08.2026 19:41 | DDoS- und Website-Manipulationsangriff auf israelische Organisationen |
| Incident | 04.08.2026 18:00 | Ransomware.live: RUPP Spritzguss (qilin) |
| Incident | 04.08.2026 08:49 | Cyberangriff auf SharePoint-Server des Bundesamts für Informatik und Telekommunikation |
| Incident | 04.08.2026 06:21 | Ransomware.live: GILDE Handwerk Macrander GmbH & Co. KG (aurora) |
| Incident | 03.08.2026 17:58 | Ransomware.live: cpu-ag.com (safepay) |
| Incident | 03.08.2026 04:54 | Ransomware.live: Hans & Jos. Kronenberg GmbH (payload) |
| Incident | 02.08.2026 15:28 | Klinikverbund Medizin Campus Bodensee von Hive-Ransomware betroffen |
| Incident | 02.08.2026 07:35 | Datenleck bei uniVersa: OpenAI-Crawler griff auf Bankdaten zu |
| Incident | 02.08.2026 00:00 | Ransomware.live: Alcon Inc. (shinyhunters) |
| Incident | 01.08.2026 13:52 | Ransomware.live: Dienst Pack Systems (qilin) |
| Incident | 01.08.2026 13:50 | Ransomware.live: Schreiner Trockenbau GmbH (qilin) |
| Incident | 31.07.2026 18:21 | Ransomware.live: Okovolt Solartechnik (thegentlemen) |
| Incident | 30.07.2026 07:23 | Ransomware.live: Evosys Laser GmbH (aurora) |
| Incident | 28.07.2026 12:00 | Ransomware.live: Della Casa Group AG (incransom) |
| Incident | 27.07.2026 19:03 | Ransomware.live: zinorm.de (safepay) |
| Incident | 27.07.2026 19:03 | Ransomware.live: moebelmayer.de (safepay) |
| Incident | 27.07.2026 19:02 | Ransomware.live: paritaet-nrw.org (safepay) |
| Incident | 27.07.2026 19:01 | Ransomware.live: haugbuersten.de (safepay) |
| Incident | 27.07.2026 19:01 | Ransomware.live: landesmuseum.de (safepay) |
| Incident | 27.07.2026 19:00 | Ransomware.live: hst.eu (safepay) |
| Incident | 27.07.2026 18:59 | Ransomware.live: weier.org (safepay) |
| Incident | 26.07.2026 11:28 | Ransomware-Gruppe m3rx listet hydraulic-components.net als Opfer |
| Incident | 25.07.2026 17:56 | Ransomware.live: Schaad, Balass, Menzl and Partner AG (Deadlock) |
| Incident | 25.07.2026 11:59 | Ransomware-Meldung zu Guntert & Zimmerman durch Qilin |
| Incident | 25.07.2026 10:28 | Ransomware.live: GURR Abdichtungstechnik GmbH (qilin) |
| Schwachstelle | 25.07.2026 03:59 | Stored XSS in the control panel via unescaped draft name |
| Schwachstelle | 25.07.2026 03:59 | Arbitrary user password reset leading to administrator account takeover |
| Schwachstelle | 25.07.2026 03:57 | Authorization bypass: view-only Categories user can modify category structure via structures/move-element |
| Schwachstelle | 25.07.2026 03:53 | SSRF in GQL asset mutation - incomplete IP denylist + post-fetch validation |
| Schwachstelle | 25.07.2026 03:53 | Incorrect path validation could potentially lead to path traversal |
| Schwachstelle | 25.07.2026 03:52 | Authenticated leak of secret environment variables |
| Schwachstelle | 25.07.2026 03:08 | Authenticated RCE through Twig sandbox escape |
| Schwachstelle | 25.07.2026 03:07 | Passkey login accepts replayed WebAuthn assertions |
| Schwachstelle | 25.07.2026 03:06 | Arbitrary file read via SplFileObject in non-sandboxed template contexts |
| Schwachstelle | 25.07.2026 03:05 | Authenticated RCE via `condition.config` JSON cleanse bypass |
| Schwachstelle | 25.07.2026 03:02 | Missing authorization check allows non-admin control panel users to reorder Global Sets |
| Schwachstelle | 25.07.2026 03:01 | Missing authorization check allows non-admin control panel users access to user registration metrics |
| Incident | 24.07.2026 13:20 | Ransomware.live: Zynex (Booba Project) |
| Incident | 24.07.2026 09:52 | Ransomware.live: metrabyte.cloud (apt73) |
| Incident | 24.07.2026 01:25 | Ransomware.live: autismuslink.ch (incransom) |
| Incident | 23.07.2026 15:05 | Ransomware.live: Wunschkind Klinik Dr Brunbauer (thegentlemen) |
| Incident | 23.07.2026 00:00 | Stadtverwaltung Döbeln |
| Incident | 21.07.2026 15:10 | Ransomware.live: RehaVital Gesundheitsservice GmbH (qilin) |
| Incident | 20.07.2026 19:07 | Ransomware.live: wdk.de (safepay) |
| Incident | 20.07.2026 19:06 | Ransomware.live: jaecklin-industrial.de (safepay) |
| Incident | 20.07.2026 19:05 | Ransomware.live: lbb-treuhand.de (safepay) |
| Incident | 20.07.2026 19:05 | Ransomware.live: timetex.de (safepay) |
| Incident | 20.07.2026 19:04 | Ransomware.live: stroebel-gruppe.de (safepay) |
| Incident | 20.07.2026 19:03 | Ransomware.live: cenesco.de (safepay) |
| Incident | 20.07.2026 19:02 | Ransomware.live: mende-grundbesitz.de (safepay) |
| Incident | 20.07.2026 00:00 | Externer Angriff auf kommunalen IT-Dienstleister Lecos |
| Incident | 18.07.2026 09:58 | Ransomware-Gruppe threeam listet tws-tac.net als Opfer |
| Incident | 18.07.2026 00:00 | Stadtverwaltung Wriezen |
| Incident | 16.07.2026 13:00 | Ransomware-Gruppe thegentlemen meldet Hanseata als Opfer |
| Incident | 16.07.2026 12:59 | Ransomware-Meldung zu Landesbibliothek Coburg durch Gruppe thegentlemen |
| Incident | 16.07.2026 00:00 | Verbandsverwaltung Rhein-Nahe |
| Incident | 16.07.2026 00:00 | Externer Angriff auf die Stadtverwaltung Wiesbaden |
| Incident | 13.07.2026 21:31 | Datendiebstahl bei Lidl nach Vorfall bei externem Dienstleister |
| Incident | 13.07.2026 12:00 | DDoS-Attacke stört Nah.SH-Website in Schleswig-Holstein |
| Incident | 13.07.2026 06:30 | Cyberangriff auf Medizintechnikhersteller Zuther+Hautmann in Podcast thematisiert |
| Incident | 12.07.2026 13:57 | Internetseiten von Stadtwerken und Verkehrsbetrieben in Leipzig mutmaßlich gehackt |
| Incident | 12.07.2026 05:36 | ZEGO Textilveredelungszentrum stellt nach Cyberangriff Insolvenzantrag |
| Incident | 11.07.2026 09:44 | Mutmaßlicher Hackerangriff auf argentinischen Fußballverband AFA |
| Incident | 11.07.2026 09:22 | Cyberangriff auf den argentinischen Fußballverband |
| Incident | 11.07.2026 07:20 | Ransomware-Meldung zu INTERNET AG durch Gruppe thegentlemen |
| Incident | 10.07.2026 15:50 | Lidl Online informiert Kunden über Datendiebstahl |
| Incident | 10.07.2026 13:12 | Ransomware.live: WH Müller (Deadlock) |
| Incident | 10.07.2026 13:01 | Ransomware.live: EFCA (Deadlock) |
| Incident | 10.07.2026 12:58 | Ransomware.live: 8.2 Group e.V. (Deadlock) |
| Incident | 10.07.2026 12:57 | Ransomware.live: Dyhrberg AG Switzerland (Deadlock) |
| Incident | 10.07.2026 12:55 | Ransomware.live: IFC Eur (Deadlock) |
| Incident | 10.07.2026 00:55 | Cyberangriff legt Produktion bei ZEGO wochenlang lahm und führt zu Insolvenz |
| Incident | 08.07.2026 11:45 | Deutsche Bank bestätigt Drittanbieter-Datenpanne nach Ransomware-Behauptung |
| Incident | 02.07.2026 10:00 | Externer Angriff auf die Stadtverwaltung Furtwangen führt zu Notbetrieb |
| Incident | 30.06.2026 10:00 | Stadtverwaltung Darmstadt |
| Incident | 29.06.2026 10:00 | Stadtverwaltung Schriesheim |
| Incident | 18.06.2026 10:00 | Stadtverwaltung Oranienburg |
| Schwachstelle | 16.06.2026 04:53 | Blind SSRF and Arbitrary JavaScript Injection via Host Header Poisoning in actionResourceJs |
| Schwachstelle | 16.06.2026 04:49 | Potential authenticated Remote Code Execution via referrer redirect |
| Schwachstelle | 16.06.2026 04:47 | Stored XSS via Structure entry title in table view |
| Schwachstelle | 16.06.2026 04:43 | Sensitive File Disclosure / Server-Side File Read |
| Schwachstelle | 16.06.2026 04:37 | DOM XSS via GitHub issue title in CraftSupport widget |
| Incident | 05.06.2026 10:00 | Cyberangriff auf die Gemeindeverwaltung Dallgow-Döberitz |
| Schwachstelle | 02.06.2026 01:20 | Authenticated "assets/preview-thumb" discloses signed fallback transform preview link to CP users without asset-view permission |
| Schwachstelle | 02.06.2026 01:18 | RCE via missing cleanseConfig in FieldsController::actionRenderCardPreview |
| Schwachstelle | 02.06.2026 01:17 | Authenticated path traversal in `assets/icon` allows local `.svg` file read |
| Schwachstelle | 29.05.2026 00:21 | Missing peer-permission check in "AssetsController::actionDeleteFolder" allows deletion of other users' assets |
| Schwachstelle | 29.05.2026 00:20 | Unauthorized Deletion of Source Assets During File Replacement |
| Schwachstelle | 29.05.2026 00:20 | Unauthorized Deletion of Destination Folders During Forced Moves |
| Schwachstelle | 29.05.2026 00:19 | Mass assignment via id in newAttributes during bulk duplicate overwrites existing elements |
| Schwachstelle | 29.05.2026 00:19 | Authorization bypass in `entries/move-to-section` via missing target-section save check |
| Schwachstelle | 29.05.2026 00:18 | Authorship spoofing in `entries/save-entry` via pre-check/post-mutation authorization gap |
| Incident | 21.05.2026 10:00 | Stadt Kiel zahlt 68.000 Euro nach BEC-Betrug |
| Incident | 19.05.2026 10:00 | Stadtverwaltung Aachen |
| Incident | 19.05.2026 10:00 | Stadtverwaltung Warendorf |
| Incident | 13.05.2026 09:17 | Foxconn von Ransomware-Angriff betroffen |
| Incident | 07.05.2026 10:00 | Stadtverwaltung Elmshorn |
| Incident | 30.04.2026 10:00 | Kommunaler IT-Dienstleister KommWis |
| Incident | 29.04.2026 12:46 | Ransomware-Angriff auf Schulzentrum B3 in Bruck an der Mur |
| Schwachstelle | 27.04.2026 20:09 | Potential authenticated Remote Code Execution via malicious attached Behavior |
| Schwachstelle | 27.04.2026 20:09 | Missing Authorization in GraphQL Address Resolver Allows Cross-Scope PII Disclosure |
| Schwachstelle | 27.04.2026 20:08 | Missing Volume Permission Check in AssetsController::actionShowInFolder Allows Information Disclosure |
| Incident | 23.04.2026 00:00 | Externer Angriff auf die Kreisverwaltung Ahrweiler |
| Incident | 17.04.2026 00:00 | Externer Angriff auf die Kreisverwaltung Spree-Neiße |
| Incident | 16.04.2026 00:00 | Externer Angriff auf Verbandsgemeindeverwaltung Sprendlingen-Gensingen |
| Schwachstelle | 13.04.2026 19:51 | Host header injection leads to SSRF via resource-js endpoint |
| Schwachstelle | 13.04.2026 19:50 | Server-Side Request Forgery (SSRF) in Craft CMS with Asset Uploads Mutations |
| Schwachstelle | 13.04.2026 19:50 | Missing Authorization Check on User Group Removal via save-permissions Action |
| Incident | 31.03.2026 03:27 | Ransomware-Angriff auf Marktgemeinde Langenzersdorf führt zu Event-Absagen |
| Schwachstelle | 24.03.2026 05:01 | Authorization bypass in "entries/move-to-section" allows control panel user to move entries without section permissions |
| Schwachstelle | 24.03.2026 05:00 | Potential authenticated Remote Code Execution via malicious attached Behavior |
| Schwachstelle | 24.03.2026 04:54 | Authorized asset "preview file" requests bypass allows users without asset access to retrieve private preview metadata |
| Schwachstelle | 24.03.2026 04:50 | Anonymous "assets/image-editor" calls returns private asset editor metadata to unauthorized users |
| Schwachstelle | 24.03.2026 04:50 | Anonymous "generate transform" calls for assets can expose private assets via transform URL |
| Schwachstelle | 24.03.2026 04:49 | Low-privilege users could read private asset contents when editing an asset (IDOR) |
| Schwachstelle | 24.03.2026 04:48 | Unauthenticated users could execute project configuration sync operations that should be restricted trusted users |
| Schwachstelle | 20.03.2026 00:00 | Craft CMS Code Injection Vulnerability |
| Schwachstelle | 16.03.2026 17:30 | Privilege Escalation/Bypass through UsersController->actionImpersonateWithToken() |
| Schwachstelle | 16.03.2026 17:30 | Incomplete fix for GHSA-7jx7-3846-m7w7: Behavior injection RCE ElementIndexesController and FieldsController |
| Schwachstelle | 16.03.2026 17:30 | Incomplete fix for GHSA-7jx7-3846-m7w7: Behavior injection RCE via EntryTypesController |
| Schwachstelle | 16.03.2026 17:30 | Path Traversal in AssetsController |
| Schwachstelle | 16.03.2026 17:29 | Stored XSS in Revision Context Menu |
| Schwachstelle | 09.03.2026 22:05 | ElementSearchController Blind SQL Injection (Bypass of GHSA-2453-mppf-46cj) |
| Schwachstelle | 09.03.2026 22:04 | Stored XSS via User Group Name in User Permissions Page |
| Schwachstelle | 09.03.2026 22:02 | RCE vulnerability via relational conditionals in the control panel |
| Schwachstelle | 09.03.2026 22:01 | Potential information disclosure vulnerability in preview tokens |
| Schwachstelle | 09.03.2026 22:00 | Reflective XSS via incomplete return URL sanitization |
| Schwachstelle | 03.03.2026 19:07 | Unauthenticated activation email trigger with potential user enumeration |
| Schwachstelle | 02.03.2026 23:09 | Potential authenticated Remote Code Execution via Twig SSTI |
| Schwachstelle | 02.03.2026 23:09 | Twig Function Blocklist Bypass |
| Schwachstelle | 02.03.2026 23:09 | Permission Bypass and IDOR in Duplicate Entry Action |
| Schwachstelle | 02.03.2026 23:09 | Entries Authorship Spoofing via Mass Assignment |
| Schwachstelle | 02.03.2026 23:05 | Authenticated RCE via "craft.app.fs.write()" in Twig Templates |
| Schwachstelle | 02.03.2026 23:05 | Multiple Stored XSS in Settings Names and Field Options |
| Schwachstelle | 02.03.2026 23:05 | IDOR via GraphQL @parseRefs |
| Schwachstelle | 02.03.2026 23:04 | Authenticated RCE via Twig SSTI - create() function + Symfony Process gadget |
| Incident | 27.02.2026 00:00 | Externer Angriff auf Stadtverwaltung Konstanz |
| Schwachstelle | 23.02.2026 19:29 | Stored XSS in Table Field via "Row Heading" Column Type |
| Schwachstelle | 23.02.2026 19:29 | Stored XSS in Table Field via "HTML" Column Type |
| Schwachstelle | 23.02.2026 19:29 | Cloud Metadata SSRF Protection Bypass via DNS Rebinding |
| Schwachstelle | 23.02.2026 19:29 | Cloud Metadata SSRF Protection Bypass via IPv6 Resolution |
| Schwachstelle | 23.02.2026 19:28 | Race condition in Token Service potentially allows for token usage greater than the token limit |
| Schwachstelle | 09.02.2026 18:04 | Stored XSS in Entry Types Name |
| Schwachstelle | 09.02.2026 18:04 | Potential authenticated Remote Code Execution via malicious attached Behavior |
| Schwachstelle | 09.02.2026 18:03 | GraphQL Asset Mutation Privilege Escalation |
| Schwachstelle | 09.02.2026 18:03 | Stored XSS in Number Prefix & Suffix Fields |
| Schwachstelle | 09.02.2026 18:02 | SQL Injection in Element Indexes via `criteria[orderBy]` |
| Schwachstelle | 09.02.2026 18:02 | SSRF in GraphQL Asset Mutation via HTTP Redirect |
| Schwachstelle | 09.02.2026 18:01 | SSRF in GraphQL Asset Mutation via Alternative IP Notation |
| Schwachstelle | 09.02.2026 18:01 | save_images_Asset graphql mutation can be abused to exfiltrate AWS credentials of underlying host |
| Incident | 27.01.2026 00:00 | Externer Angriff auf die Stadtverwaltung Schorndorf |
| Incident | 16.01.2026 00:00 | Externer Angriff auf die Stadtverwaltung Heinsberg |
| Incident | 10.01.2026 00:00 | Externer Angriff auf die Stadtverwaltung Halle (Saale) |
| Schwachstelle | 03.01.2026 22:20 | Potential information disclosure via unchecked asset relocation |
| Schwachstelle | 03.01.2026 22:19 | Server-Side Request Forgery (SSRF) via GraphQL Asset Upload Mutation |
| Schwachstelle | 03.01.2026 22:17 | Potential authenticated Remote Code Execution via Twig SSTI |
| Schwachstelle | 03.01.2026 22:16 | Potential authenticated Remote Code Execution via malicious attached Behavior |
| Schwachstelle | 03.01.2026 22:14 | Unauthenticated users can trigger a database backup |
| Incident | 02.01.2026 00:00 | Externer Angriff auf die Stadtverwaltung Lübben |
| Incident | 02.01.2026 00:00 | Externer Angriff auf Amtsverwaltung Amt Falkenberg-Höhe |
| Incident | 21.11.2025 00:00 | Externer Angriff auf die Stadtverwaltung Steinau an der Straße |
| Incident | 21.11.2025 00:00 | Externer Angriff auf die Stadtverwaltung Mainz |
| Incident | 20.11.2025 00:00 | Externer Angriff auf die Stadtverwaltung Goslar |
| Incident | 18.11.2025 00:00 | Externer Angriff auf die Stadtverwaltung Wuppertal |
| Incident | 06.11.2025 00:00 | Mutmaßlicher Cyberangriff auf Stadtverwaltung Ludwigshafen am Rhein |
| Incident | 03.11.2025 00:00 | Externer Angriff auf die Stadtverwaltung Trier |
| Incident | 03.11.2025 00:00 | Externer Angriff auf die Stadtverwaltung Schwarzenbek |
| Incident | 23.10.2025 10:39 | Ransomware-Angriff auf Mondi Resort am Grundlsee |
| Incident | 20.10.2025 00:00 | Externer Angriff auf die Gemeindeverwaltung Untereisesheim |
| Incident | 14.10.2025 00:00 | Externer Angriff auf die Kreisverwaltung Rastatt |
| Incident | 07.10.2025 00:00 | Externer Angriff auf die Stadtverwaltung Hohen Neuendorf |
| Incident | 12.09.2025 00:00 | Externer Angriff auf die Gemeindeverwaltung Glatten |
| Incident | 28.08.2025 00:00 | Externer Angriff auf die Kreisverwaltung Schmalkalden-Meiningen |
| Schwachstelle | 25.08.2025 16:48 | Potential Remote Code Execution via Twig SSTI |
| Incident | 12.08.2025 00:00 | Externer Angriff auf Gemeindeverwaltung Hoppegarten |
| Schwachstelle | 08.08.2025 18:19 | Potential bypass for CVE-2025-23209 |
| Incident | 29.07.2025 00:00 | Webseiten von Kommunen Ziel von DDoS-Angriffen |
| Incident | 24.07.2025 00:00 | Externer Angriff auf Gemeindeverwaltung Bodman-Ludwigshafen |
| Incident | 10.07.2025 00:00 | Externer Angriff auf die Kreisverwaltung Odenwaldkreis |
| Incident | 09.07.2025 00:00 | Externer Angriff auf die Stadtverwaltung Nürnberg |
| Incident | 20.06.2025 00:00 | Externer Angriff auf die Gemeindeverwaltung Lotte |
| Incident | 03.06.2025 00:00 | Externer Angriff auf die Gemeindeverwaltung Ostercappeln |
| Schwachstelle | 02.06.2025 00:00 | Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability |
| Schwachstelle | 02.06.2025 00:00 | Craft CMS Code Injection Vulnerability |
| Incident | 22.05.2025 00:00 | Externer Angriff auf die Kreisverwaltung Bodenseekreis |
| Schwachstelle | 05.05.2025 01:02 | Potential Remote Code Execution via Twig SSTI |
| Incident | 24.04.2025 00:00 | Externer Angriff auf die Stadtverwaltung Ellwangen |
| Incident | 16.03.2025 00:00 | Externer Angriff auf die Gemeindeverwaltung Kirkel |
| Schwachstelle | 20.02.2025 00:00 | Craft CMS Code Injection Vulnerability |
| Incident | 13.02.2025 00:00 | Externer Angriff auf Stadtverwaltungen Garching und Unterschleißheim sowie Kreisverwaltung München |
| Incident | 20.12.2024 00:00 | Externer Angriff auf die Gemeindeverwaltung Kaisersbach |
| Incident | 18.11.2024 00:00 | Externer Angriff auf Amtsverwaltung Amt Bergen auf Rügen |
| Incident | 15.11.2024 00:00 | Externer Angriff auf die Kreisverwaltung Aurich |
| Incident | 14.11.2024 00:00 | Externer Angriff auf die Stadtverwaltung Aschaffenburg |
| Schwachstelle | 13.11.2024 00:30 | Local File System Validation Bypass Leading to File Overwrite, Sensitive File Access, and Potential Code Execution |
| Schwachstelle | 13.11.2024 00:30 | Potential Remote Code Execution via missing path normalization & Twig SSTI |
| Schwachstelle | 13.11.2024 00:29 | Read Arbitrary System Files |
| Incident | 23.10.2024 00:00 | Externer Angriff auf die Kreisverwaltung Kitzingen |
| Incident | 08.10.2024 00:00 | Externer Angriff auf Verbandsgemeinde Elbe-Heide |
| Schwachstelle | 09.09.2024 16:26 | Stored XSS in breadcrumb list and title fields |
| Schwachstelle | 25.07.2024 15:58 | TOTP Token Stays Valid After Use |
| Incident | 20.03.2024 00:00 | Externer Angriff auf Stadtverwaltung Rheinberg |
| Incident | 11.03.2024 00:00 | Externer Angriff auf die Stadtverwaltung Fürth |
| Incident | 28.02.2024 00:00 | Externer Angriff auf die Stadtverwaltung Bad Schwalbach |
| Incident | 27.02.2024 00:00 | Externer Angriff auf die Kreisverwaltung Neuburg-Schrobenhausen |
| Incident | 07.02.2024 00:00 | Externer Angriff auf die Gemeindeverwaltung Petersberg |
| Incident | 01.02.2024 00:00 | Externer Angriff auf die Kreisverwaltung Kelheim |
| Schwachstelle | 03.01.2024 01:10 | Privilege Escalation |
| Incident | 28.11.2023 00:00 | Externer Angriff auf Kreisverwaltung Vorpommern-Rügen |
| Incident | 22.11.2023 00:00 | Externer Angriff auf Zweckverband gemeindliche Datenverarbeitung im Landkreis Neu-Ulm |
| Incident | 18.11.2023 00:00 | Externer Angriff auf die Stadtverwaltung Mössingen |
| Incident | 15.11.2023 00:00 | Externer Angriff auf die Stadtverwaltung Neuss |
| Incident | 08.11.2023 00:00 | Externer Angriff auf die Stadtverwaltung Itzehoe |
| Incident | 30.10.2023 00:00 | Ransomware-Befall bei Zweckverband Südwestfalen-IT: Forensik-Bericht enthüllt Sicherheitsversäumnisse |
| Incident | 11.10.2023 00:00 | Externer Angriff auf die Gemeindeverwaltung Grasellenbach |
| Incident | 02.10.2023 00:00 | Externer Angriff auf die Stadtverwaltung Essen |
| Schwachstelle | 13.09.2023 04:39 | Remote Code Execution |
| Incident | 01.09.2023 00:00 | Externer Angriff auf Verbandsgemeindeverwaltung Wörrstadt |
| Incident | 31.08.2023 00:00 | Externer Angriff auf die Stadtverwaltung Alzey |
| Schwachstelle | 19.08.2023 00:43 | Remote Code Execution via validatePath bypass |
| Incident | 19.06.2023 00:00 | Externer Angriff auf die Gemeindeverwaltung Hülben |
| Incident | 01.06.2023 00:00 | Externer Angriff auf die Stadtverwaltung Kaltennordheim |
| Incident | 30.05.2023 00:00 | Externer Angriff auf Stadtverwaltung Bad Langensalza |
| Schwachstelle | 25.05.2023 18:09 | Stored XSS in review volumne |
| Schwachstelle | 25.05.2023 18:09 | Stored XSS in indexedVolumes |
| Schwachstelle | 25.05.2023 18:09 | XSS in RSS widget feed |
| Schwachstelle | 25.05.2023 18:08 | Stored XSS in Quick Post widget error message |
| Incident | 25.05.2023 00:00 | Externer Angriff auf die Stadtverwaltung Mayen |
| Schwachstelle | 19.05.2023 02:51 | Remote Code Execution via unrestricted file extension |
| Incident | 11.05.2023 00:00 | Externer Angriff auf die Kreisverwaltung Ludwigsburg |
| Schwachstelle | 05.05.2023 16:52 | XSS in RSS feed widget |
| Incident | 27.04.2023 00:00 | Externer Angriff auf die Gemeindeverwaltung Birkenfeld im Enzkreis |
| Incident | 16.03.2023 00:00 | Externer Angriff auf die Gemeindeverwaltung Elbtal |
| Incident | 07.03.2023 00:00 | Externer Angriff auf die Stadtverwaltung Rastatt |
| Incident | 07.03.2023 00:00 | Externer Angriff auf die Stadtverwaltung Bad Kreuznach |
| Schwachstelle | 03.03.2023 16:34 | Stored XSS Injection Vulnerability |
| Incident | 24.02.2023 00:00 | Externer Angriff auf die Stadtverwaltung Rodgau |
| Incident | 20.02.2023 00:00 | Externer Angriff auf die Kreisverwaltung Böblingen |
| Incident | 02.02.2023 00:00 | Externer Angriff auf die Gemeindeverwaltung Gerstetten |
| Incident | 29.12.2022 00:00 | Externer Angriff auf die Stadtverwaltung Potsdam |
| Incident | 29.11.2022 00:00 | Externer Angriff auf die Stadtverwaltung Drensteinfurt |
| Incident | 24.10.2022 00:00 | Externer Angriff auf die Kreisverwaltung Rhein-Pfalz-Kreis |
| Incident | 24.10.2022 00:00 | Externer Angriff auf Kreisverwaltung München |
| Incident | 09.09.2022 00:00 | Externer Angriff auf die Gemeindeverwaltung Dorn-Dürkheim |
| Incident | 07.09.2022 00:00 | Externer Angriff auf die Gemeindeverwaltung Egelsbach |
| Incident | 06.09.2022 00:00 | Externer Angriff auf die Stadtverwaltung Stockach |
| Incident | 13.07.2022 00:00 | Externer Angriff auf die Stadtverwaltung Burladingen |
| Incident | 09.07.2022 00:00 | Externer Angriff auf die Gemeindeverwaltung Ellefeld |
| Incident | 13.06.2022 00:00 | Stadt- und Gemeindeverwaltungen Odenwaldkreis |
| Incident | 06.06.2022 00:00 | Externer Angriff auf die Kreisverwaltung Ostallgäu |
| Incident | 24.05.2022 00:00 | Externer Angriff auf die Gemeindeverwaltung Bissingen |
| Incident | 13.05.2022 00:00 | Externer Angriff auf die Gemeindeverwaltung Murnau am Staffelsee |
| Schwachstelle | 04.04.2022 18:22 | XSS Injection Vulnerability |
| Incident | 21.03.2022 00:00 | Externer Angriff auf die Stadtverwaltung Dingolfing |
| Incident | 10.03.2022 00:00 | Externer Angriff auf die Stadtverwaltung Suhl |
| Incident | 09.03.2022 00:00 | Externer Angriff auf die Stadtverwaltung Bochum |
| Incident | 16.12.2021 00:00 | Externer Angriff auf die Stadtverwaltung Schmalkalden |
| Incident | 15.12.2021 00:00 | Externer Angriff auf die Kreisverwaltung Mansfeld-Südharz |
| Incident | 01.12.2021 00:00 | Externer Angriff auf die Stadtverwaltung Seehausen (Altmark) |
| Incident | 16.11.2021 00:00 | Externer Angriff auf die Stadtverwaltung Sassnitz |
| Incident | 21.10.2021 00:00 | Externer Angriff auf die Stadtverwaltung Witten |
| Schwachstelle | 15.10.2021 01:13 | CSV Injection Vulnerability |
| Incident | 15.10.2021 00:00 | Externer Angriff auf Zweckverband SIS/KSM |
| Incident | 05.09.2021 00:00 | Externer Angriff auf die Kreisverwaltung Wesel |
| Incident | 23.08.2021 00:00 | Externer Angriff auf die Gemeindeverwaltung Hüttenberg |
| Incident | 04.08.2021 00:00 | Externer Angriff auf die Gemeindeverwaltung Hohenpeißenberg |
| Incident | 14.07.2021 00:00 | Externer Angriff auf Stadtverwaltung Geisenheim |
| Incident | 07.07.2021 00:00 | Externer Angriff auf die Kreisverwaltung Anhalt-Bitterfeld |
| Incident | 15.04.2021 00:00 | Externer Angriff auf die Gemeindeverwaltung Kammeltal |
| Incident | 02.04.2021 00:00 | Externer Angriff auf Samtgemeindeverwaltung Rodenberg |
| Incident | 30.03.2021 00:00 | Externer Angriff auf die Stadtverwaltung Angermünde |
| Incident | 24.03.2021 00:00 | Externer Angriff auf die Gemeindeverwaltung Schöneiche bei Berlin |
| Incident | 11.03.2021 00:00 | Externer Angriff auf die Stadtverwaltung Dippoldiswalde |
| Incident | 10.03.2021 00:00 | Externer Angriff auf die Stadtverwaltung Beverungen |
| Incident | 10.03.2021 00:00 | Externer Angriff auf die Stadtverwaltung Stadtlohn |
| Incident | 09.03.2021 00:00 | Externer Angriff auf die Stadtverwaltung Ebeleben |
| Incident | 03.03.2021 00:00 | Externer Angriff auf die Gemeindeverwaltung Fahrenzhausen |
| Incident | 03.03.2021 00:00 | Externer Angriff auf die Gemeindeverwaltung Kranzberg |
| Incident | 20.01.2021 00:00 | Externer Angriff auf die Stadtverwaltung Bendorf |
| Incident | 06.01.2021 00:00 | Externer Angriff auf die Stadtverwaltung Hannover |
| Incident | 21.05.2020 00:00 | Externer Angriff auf die Stadtverwaltung Langenhagen |
| Incident | 26.03.2020 00:00 | Externer Angriff auf die Stadtverwaltung Hof (Saale) |
| Incident | 24.01.2020 00:00 | Externer Angriff auf die Stadtverwaltung Brandenburg an der Havel |
| Incident | 02.01.2020 00:00 | Externer Angriff auf die Stadtverwaltung Alsfeld |