{"id":"CVE-2024-37843","aliases":["GHSA-hq4f-mv3q-8wcv"],"url":"https://o3.security/vulnerability/CVE-2024-37843","summary":"Craft CMS SQL injection vulnerability via the GraphQL API endpoint","details":"Craft CMS up to v3.7.31 was discovered to contain a SQL injection vulnerability via the GraphQL API endpoint.","published":"2024-06-25T00:00:00Z","modified":"2026-08-07T11:31:27.616740576Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.51282,"percentile":0.98827,"asOf":"2026-07-28"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"Packagist","name":"craftcms/cms","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/37xxx/CVE-2024-37843.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-37843"},{"type":"ARTICLE","url":"https://blog.smithsecurity.biz/craft-cms-unauthenticated-sqli-via-graphql"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:27.616740576Z"}}