Vulnerability Intelligence Report
Craft CMS Allows Remote Code Execution
CVE-2025-32432
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.
CISA KEV
Nuclei Template
SSVC: Active Exploitation
Automatable
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.0
EPSS Probability:99.73%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-94 ↗CWE-94: Improper Control of Generation of Code ('Code Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| craftcms | cms | >= 3.0.0-RC1, < 3.9.15 (affected), >= 4.0.0-RC1, < 4.14.15 (affected), >= 5.0.0-RC1, < 5.6.17 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
CISA KEV
ACTIVE IN CATALOG
Nuclei Template
SCANNER AVAILABLE
EPSS Score
99.734%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2025-04-08T10:54:58 |
| Published | 2025-04-25T15:04:06 |
| Last Updated | 2026-03-21T04:00:57 |
Community Chatter & Buzz