{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:cca76c26-320c-55b5-8849-adc19a5597ef",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare",
      "type": "library",
      "group": "craftcms",
      "name": "cms",
      "version": "3.9.15-p5+tuxcare",
      "purl": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:1a69a94b-4d4a-5181-93b6-f2c1a01b933e",
      "id": "AIKIDO-2025-10090",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10090 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebe84a6c-a156-53c9-be6a-c0add4671647",
      "id": "AIKIDO-2025-10859",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability AIKIDO-2025-10859 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2f5ddb79-c759-5d2b-98fd-9c99e1485b72",
      "id": "CVE-2022-37251",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2022-37251 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2022-37251 (XSS via Drafts) has already been fixed in the target repository. The target contains the vendor's patches from upstream Craft CMS 3.7.55.2 (September 2022) that address this CVE."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b91e9f6e-7f77-557d-97c9-b22a2053cf5c",
      "id": "CVE-2023-30179",
      "analysis": {
        "state": "false_positive",
        "detail": "Vulnerability CVE-2023-30179 is a false positive for craftcms/cms 3.9.15-p5+tuxcare."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ddef341-d562-5c0f-97b1-df059f71274f",
      "id": "CVE-2023-31144",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-31144 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-31144 (XSS via unescaped slashes in JSON) is already fixed in the target repository. The fix - removing JSON_UNESCAPED_SLASHES from the default encoding options - is present in src/helpers/Json.php at lines 36-39, matching the vendor patch exactly. All call sites have been updated to use the safe default."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f49d8f27-97b9-587b-9961-420b1b45df20",
      "id": "CVE-2023-33195",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33195 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33195. The vulnerability was specific to version 4.x's externalLink macro which doesn't exist in version 3.x. Version 3.9.15 uses a safer architecture where RSS feed data is passed via the 'text' parameter which is automatically HTML-encoded by tagFunction (Extension.php:1567), preventing XSS attacks."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9b30caea-f7b0-5c40-8fc2-60f96ec6fbf2",
      "id": "CVE-2023-33196",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33196 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 The target repository (Craft CMS 3.9.15) uses server-side Twig templates with built-in HTML auto-escaping, preventing XSS through file paths and volume URIs. The upstream vulnerability (CVE-2023-33196) affects version 4.4.7 which uses client-side TypeScript for HTML generation without escaping. This is a fundamental architectural difference between versions 3.x and 4.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:269a7166-0e4f-5862-9dd7-5b9e1c19d1ac",
      "id": "CVE-2023-33197",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-33197 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2023-33197. The vulnerable feature (session overview table with client-side HTML rendering of volume names) does not exist in version 3.9.15. The target uses server-side Twig rendering with automatic HTML escaping, and volume names are never sent to JavaScript for client-side HTML construction."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7c9f09dd-0f9d-55aa-b3f2-2d01e9b80798",
      "id": "CVE-2023-33495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-33495 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:965b834e-9cde-5424-991a-f4d50b1eb212",
      "id": "CVE-2023-36260",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-36260 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 The target repository is Craft CMS core (craftcms/cms), while the vulnerability CVE-2023-36260 exists in the Feed Me plugin (craftcms/feed-me), which is a separate third-party plugin codebase. The Feed Me plugin is not bundled with or integrated into Craft CMS core. The vulnerable code (FeedsController.php with actionSaveFeed method) does not exist anywhere in the target repository."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:073dfc3d-1105-5a8f-a2eb-211d6024229e",
      "id": "CVE-2023-40035",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-40035 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2023-40035 has been fixed in the target repository. The target (Craft CMS 3.9.15-p3+tuxcare) contains both security fixes: (1) Component::cleanseConfig() method that removes malicious 'on ' and 'as ' configuration keys to prevent RCE via event handler/behavior injection, and (2) FileHelper::normalizePath() that strips 'file://' protocol wrappers. The cleanseConfig fix was added in version 3..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2a2da6f2-792f-527e-bb40-f8616b5928ab",
      "id": "CVE-2023-41892",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2023-41892 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 The target Craft CMS 3.9.15 repository already contains the fix for CVE-2023-41892. The vulnerability (RCE via Yii2 'on ' and 'as ' configuration keys) was originally patched in Craft 4.4.15 (June 2023) and backported to Craft 3.9.4 (September 2023). The target version 3.9.15 includes the Component::cleanseConfig() method that filters malicious config keys before object instantiation, matching ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4f2b0e01-f742-58bb-9f82-7b3faef79563",
      "id": "CVE-2024-21622",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-21622 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 CVE-2024-21622 is NOT present in the target repository. The target is Craft CMS version 3.9.15-p5+tuxcare, which already contains the security fix introduced in version 3.9.6. The vulnerability allowed unauthorized username modification via POST body parameters, but the fix properly restricts this to authorized contexts only (new user creation, admin users, or self-modification)."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9d02134-d6f9-5307-9dfd-bbd57a57a551",
      "id": "CVE-2024-41800",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-41800 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 does not contain TOTP authentication functionality. The vulnerability CVE-2024-41800 affects Craft CMS 5.x, which introduced TOTP-based two-factor authentication. The target version predates this feature entirely."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d44f8665-7007-5466-bdb6-fae174e52a16",
      "id": "CVE-2024-52291",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-52291 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c450b217-ba90-5447-9a6b-144cb50d872a",
      "id": "CVE-2024-52292",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-52292 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7a81e2d7-ed02-5a97-b30e-9c8aace50809",
      "id": "CVE-2024-52293",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-52293 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. already_fixed \u2014 The target repository (Craft CMS 3.9.15) already contains an equivalent and more comprehensive fix for the Twig SSTI arrow function injection vulnerability through prior TuxCare backports (PHPELSCVE-320). The defense mechanism '_checkFilterSupport()' blocks dangerous function names in Twig filter arrow parameters with a more extensive blocklist (26 functions) than the upstream patch (5 function..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:028729fe-5b7f-5b29-9b06-43af7273ea38",
      "id": "CVE-2025-23209",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-23209 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. Version 3.9.15 is not vulnerable. Summary: The target repository (Craft CMS 3.9.15-p3+tuxcare) is NOT vulnerable to CVE-2025-23209. While the CVE affects Craft 4 and 5, this Craft 3.x version has been patched by completely disabling the vulnerable database restore functionality rather than adding validation. The vulnerable code pattern (unsanitized use of dbBackupPath) no longer exists in the codebase."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:923e89ed-af6c-55e2-bd07-96eaddde59d7",
      "id": "CVE-2025-32432",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-32432 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0db59fe7-11b6-50fb-b155-99c564cde6b4",
      "id": "CVE-2025-35939",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-35939 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f6b64dca-94cf-5c4b-a83c-0ad3e31216b8",
      "id": "CVE-2025-46731",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-46731 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f22dd8c3-853b-5205-a2a1-6211573150f6",
      "id": "CVE-2025-54417",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-54417 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:da8b2514-c604-5956-ab30-9656d3e2ec5d",
      "id": "CVE-2025-57811",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-57811 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7be5125b-6603-5b40-9b79-59787d19b01e",
      "id": "CVE-2025-68436",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68436 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 The target version 3.9.15 is not affected by CVE-2025-68436. While the underlying data flaw exists (photoId is a public property without ownership validation), the architecture in version 3.9.15 prevents exploitation by regular authenticated users through permission constraints. The CVE explicitly lists versions 4.0.0-RC1+ and 5.0.0-RC1+ as affected, indicating the vulnerability was introduced ..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:162017fa-10a2-5123-830e-c327fd677617",
      "id": "CVE-2025-68437",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-68437 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:733925d2-dabf-5f02-9449-134b9df251f0",
      "id": "CVE-2025-68454",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-68454 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37601131-7245-5881-adc0-8a0bcfdd3241",
      "id": "CVE-2025-68455",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2025-68455 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. Not affected. CVE-2025-68455 targets Craft 4/5 endpoints (apply-layout-element-settings, render-card-preview) introduced with the Craft 4 field layout designer overhaul; those routes do not exist in Craft 3.9.15. The exploit relies on injecting 'as ' and 'on ' keys via Component::__set(), which only interprets those prefixes when the target extends Yii's Component class. In 3.9.15, field-layout elements extend yii\\base\\BaseObject (not Component); BaseObject::__set() throws UnknownPropertyException on 'as'/'on' keys instead of attaching a Behavior or wildcard event handler. Even if an attacker reached the config path, no malicious behavior/handler attaches. The vulnerability was introduced by a base-class change made after 3.9.15. Reopened per developer analysis; VC verdict cited FieldsController::actionRenderLayoutElementSelector but the injection sink is inert on 3.9.15."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b787e65a-2509-5647-b052-8d924d492acb",
      "id": "CVE-2025-68456",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-68456 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96486b3c-e190-56d9-b5ee-fdb3d8d9f043",
      "id": "CVE-2026-25491",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-25491 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-25491. The vulnerability affects Craft CMS versions 5.0.0-RC1 to 5.8.21 where Entry Type names are rendered via server-side PHP without HTML encoding. Version 3.9.15 uses a fundamentally different architecture (Twig/Vue.js frameworks) that provides automatic HTML escaping at multiple layers, preventing XSS attacks. The vulnerable code pattern (unescape..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9ba63d51-1f07-5d2f-81d5-066276c64e08",
      "id": "CVE-2026-25493",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25493 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:40292e75-c2e8-54dd-98de-5b880e55c58b",
      "id": "CVE-2026-25494",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25494 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9461e44c-f6c4-5d82-91c0-38480cb77683",
      "id": "CVE-2026-25495",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25495 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c71a535f-5522-5888-8156-36e090dfb60a",
      "id": "CVE-2026-25496",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-25496 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c86f2a15-203c-573e-a129-df582c5eb272",
      "id": "CVE-2026-25498",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-25498 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ced1ee14-4f23-57bf-be73-30cabdebfb87",
      "id": "CVE-2026-27126",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-27126 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. Not affected. CVE-2026-27126 (GHSA-3jh3-prx3-w6wc) is a stored XSS in the 'html' column type of editableTable.twig. Per NVD it affects craftcms/cms >=4.5.0-RC1,<4.16.19 and >=5.0.0-RC1,<5.8.23 (patched 4.16.19/5.8.23). The 'html' column type was introduced in Craft 4.5; version 3.9.15 predates it and has no 'html' column type, so it is not in the affected range. Backport MR !27 closed."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a43ce4d4-918e-5042-83e5-8e357d0214d9",
      "id": "CVE-2026-27127",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27127 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bccd797-ad9a-53f5-b04e-fdf0146c7396",
      "id": "CVE-2026-27128",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-27128 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1addcb45-406d-5e38-8e9d-2cfec0654ad7",
      "id": "CVE-2026-27129",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-27129 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d10c525-f589-550c-8d01-4e3a16cb08d2",
      "id": "CVE-2026-28783",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-28783 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:a04bb448-16c2-5ffc-b680-ed260e2ca4a5",
      "id": "CVE-2026-29069",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-29069 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:c56abd1d-15f8-5b96-84b8-059a3b9a78e1",
      "id": "CVE-2026-29113",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-29113 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f2a578a2-05ce-5f3d-80b0-c756d858f377",
      "id": "CVE-2026-31857",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31857 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Version 3.9.15 is not affected by CVE-2026-31857. The vulnerability requires the conditions system (BaseElementSelectConditionRule) which was introduced in Craft 4.x and does not exist in this 3.x version. While renderObjectTemplate() lacks sandboxing in 3.9.15, no code path exists for low-privilege authenticated users to exploit it."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:34061ace-8cae-53cb-bb00-dc15a3c58a22",
      "id": "CVE-2026-31858",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-31858 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-31858 describes a SQL injection vulnerability in ElementSearchController::actionSearch() where user-supplied criteria parameters (where, orderBy, etc.) reach SQL queries without sanitization. This controller does not exist in Craft CMS 3.9.15 (it was introduced in version 5.x). The 3.9.15 architecture uses only ElementIndexesController for element queries, which already has the unset()..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:43406ad6-ada4-5305-9605-40c3e0753bb5",
      "id": "CVE-2026-31859",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-31859 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7599e21e-c831-54b1-a7dc-1f237dfeea61",
      "id": "CVE-2026-32262",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32262 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f173a0eb-5b27-540e-8e05-212c8979fa74",
      "id": "CVE-2026-32263",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-32263 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-32263 affects Craft CMS versions 5.6.0 to 5.9.11 in the EntryTypesController. The target repository is Craft CMS version 3.9.15, which uses a different architectural approach for entry type management. The specific vulnerability pattern (parse_str \u2192 Craft::configure without cleanseConfig in EntryTypesController) does not exist in version 3.x."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1ffcee44-3b79-5132-8ad8-c2fd96f29811",
      "id": "CVE-2026-32264",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-32264 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:9e4c946e-05a5-5229-91e9-2dd015152493",
      "id": "CVE-2026-32267",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-32267 is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:60c3ff2e-85ad-50f7-9f55-32749a8103ab",
      "id": "CVE-2026-33051",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33051 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS 3.9.15 is not affected by CVE-2026-33051. The vulnerability affects versions 5.9.0-beta.1 through 5.9.10 and involves Template::raw() bypassing HTML escaping when rendering creator fullName in the revision/draft context menu. Version 3.9.15 uses a different architecture with Twig auto-escaping and jQuery .text() that prevent XSS attacks through automatic HTML entity encoding."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:7df2cd2b-29b4-58e7-8f79-87795157c648",
      "id": "CVE-2026-33157",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33157 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ed2da36-922e-57b6-ad75-3c07153e9c71",
      "id": "CVE-2026-33158",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33158 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8dbf7718-7d2e-5825-837b-86805e677417",
      "id": "CVE-2026-33159",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33159 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d643299b-3b50-5a65-8e2a-d1ca9c606d31",
      "id": "CVE-2026-33160",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33160 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:fcc83b36-a78d-5c21-afd3-70c0353279f7",
      "id": "CVE-2026-33161",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-33161 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:56c67328-ffdc-53cb-a2ed-c142973bd345",
      "id": "CVE-2026-33162",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-33162 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. Not affected. CVE-2026-33162 (cross-section entry-move authorization bypass) affects craftcms/cms 5.3.0..5.9.13 only. The move-entries-across-sections feature (EntriesController move action + Entry::canMove) was introduced in Craft 5.3 and does not exist in 3.9.15. Backport MR !36 closed as not applicable."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:37767d6e-7c59-5c95-9884-8904ecc0fce8",
      "id": "CVE-2026-41129",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41129 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. CVE-2026-41129 fix already exists in commit ea60afd3edf8799d3461c8199fe9f09145756d1b"
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d5620671-2c31-5970-8ed5-ae1fbd527d13",
      "id": "CVE-2026-41130",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41130 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 Craft CMS version 3.9.15 is not affected by CVE-2026-41130. The vulnerable actionResourceJs() method that proxies remote JavaScript resources via HTTP requests does not exist in this version. Version 3.9.15 uses a different architecture (_processResourceRequest() in Application.php) that only serves local files and never makes HTTP requests, preventing the SSRF vulnerability."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:508704bf-600c-52f2-b4e7-9d7ac97f40fc",
      "id": "CVE-2026-55790",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-55790 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2c21ccc5-de34-57b0-ae1c-7fbfa1304ca2",
      "id": "CVE-2026-55793",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-55793 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 CVE-2026-55793 does not affect Craft CMS version 3.9.15. The vulnerability was introduced in version 5.x when the code was refactored to add accessibility features. Version 3.9.15 uses a fundamentally different architecture that never interpolates entry titles into HTML during toggle creation."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5072992c-bf52-5f04-a336-f7571ef70f0c",
      "id": "GHSA-3m9m-24vh-39wx",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability GHSA-3m9m-24vh-39wx is fixed in version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ca7bd830-08ae-57aa-9cd0-f9d8e1052fe8",
      "id": "GHSA-44px-qjjc-xrhq",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-44px-qjjc-xrhq affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:f5cdfb53-d909-58e0-beda-cd1b4ea4393d",
      "id": "GHSA-6j87-m5qx-9fqp",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-6j87-m5qx-9fqp affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e9fd3b11-68fe-5e83-ba67-c8660366eab6",
      "id": "GHSA-86vw-x4ww-x467",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-86vw-x4ww-x467 does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 The specific vulnerability described in GHSA-86vw-x4ww-x467 does not affect Craft CMS version 3.9.15. The CVE references method `actionRenderCardPreview()` in FieldsController and function `Fields::createLayout()`, neither of which exist in this version. While a similar method `actionRenderLayoutElementSelector()` exists with a comparable code pattern (accepting POST config without cleanseConfi..."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:91ed337b-24da-582e-8b2e-d87eea1abe00",
      "id": "GHSA-95wr-3f2v-v2wh",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-95wr-3f2v-v2wh affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:09ad33ea-39fd-5898-9620-f067fcbb8fa1",
      "id": "GHSA-c43v-4cr8-6mvp",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability GHSA-c43v-4cr8-6mvp does not affect version 3.9.15-p5+tuxcare of craftcms/cms. not_affected \u2014 The icon-serving feature described in GHSA-c43v-4cr8-6mvp does not exist in Craft CMS version 3.9.15. The vulnerable endpoint (assets/icon), controller action (AssetsController::actionIcon), and helper functions (Assets::iconPath, Assets::iconSvg) were introduced in a later version. The target version cannot be exploited via this vulnerability because the input-receiving code path does not exist."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:28f3cad2-50eb-54cf-9aee-28c8eeb8bef4",
      "id": "GHSA-g3hp-vvqf-8vw6",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-g3hp-vvqf-8vw6 affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:36e0dcf8-e1cc-58b4-a764-ae29f3ee443f",
      "id": "GHSA-x76w-8c62-48mg",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability GHSA-x76w-8c62-48mg affects version 3.9.15-p5+tuxcare of craftcms/cms."
      },
      "affects": [
        {
          "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:composer/craftcms/cms@3.9.15-p5+tuxcare"
    }
  ]
}