← Back to CVE List
Vulnerability Intelligence Report
Craft CMS Allows Remote Code Execution

CVE-2025-32432

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.

CISA KEV Nuclei Template SSVC: Active Exploitation Automatable
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.0
EPSS Probability:99.73%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-94 ↗CWE-94: Improper Control of Generation of Code ('Code Injection')

Affected Products & Versions

Vendor Product Affected Versions
craftcms cms >= 3.0.0-RC1, < 3.9.15 (affected), >= 4.0.0-RC1, < 4.14.15 (affected), >= 5.0.0-RC1, < 5.6.17 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.734%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2025-04-08T10:54:58
Published2025-04-25T15:04:06
Last Updated2026-03-21T04:00:57

LINK COPIED TO CLIPBOARD