Craft CMS Amazon S3 Plugin Information Disclosure Vulnerability

Vulnerability

A low-severity information disclosure vulnerability exists in the Amazon S3 for Craft CMS plugin, specifically in versions 2.0.2 through 2.2.4. The issue allows unauthenticated users to access a list of S3 buckets that the plugin can interact with. This vulnerability arises because the `BucketsController->actionLoadBucketData()` endpoint permits unauthenticated users, provided they have a valid CSRF token, to view the buckets accessible to the plugin.

Impact

Exploitation of this vulnerability allows for unauthorized access to information about S3 buckets that the plugin can access, potentially leading to further information disclosure or misuse of that access.

Remediation

Users are advised to update the Amazon S3 for Craft CMS plugin to version 2.2.5 to address this vulnerability.

Added: Mar 18, 2026, 4:21 AM
Updated: Mar 18, 2026, 4:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
6.7
remediation
0.0
relevance
4.1
threat
3.2
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.