Synced 30 Sept 2026 23:45 UTC Account
← All products

CVE-2025-32432

CRITICAL severity · CVSS 10 · Code injection · actively exploited (CISA KEV)
10CVSS CRITICAL exploited
Actively exploited in the wild (CISA Known Exploited Vulnerabilities). Added to KEV 2026-03-20. US federal agencies must patch by 2026-04-03.

Summary

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.

Impact & exploitability

Attack vectorNetwork
Attack complexityLow
Privileges requiredNone
User interactionNone
Confidentiality impactHigh
Integrity impactHigh
Availability impactLow
Exploit probability (EPSS)100%

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L

Affected products we track (1)

Recommendation

This vulnerability is being actively exploited in the wild — patch affected products urgently. Open any affected product above for its exact safe version.

Official patch: https://github.com/craftcms/cms/commit/e1c85441fa47eeb7c688c2053f25419bc0547b47 ↗