Vulnerability record · CVE-2023-41892 · published 13 September 2023
CVE-2023-41892: Craft CMS code injection enables unauthenticated remote code execution
Craftcms · Craft Cms
Craft CMS versions before 4.4.15 contain a code injection flaw (CWE-94) that allows remote code execution. The vendor describes it as a high-impact, low-complexity attack vector and fixed it in 4.4.15. Because it is network-reachable and needs no credentials, any exposed Craft install is at serious risk.
Description
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction required, plus very high EPSS and public exploit code, makes this an urgent patch-first issue.
What it is
Craft CMS versions before 4.4.15 contain a code injection flaw (CWE-94) that allows remote code execution. The vendor describes it as a high-impact, low-complexity attack vector and fixed it in 4.4.15. Because it is network-reachable and needs no credentials, any exposed Craft install is at serious risk.
Impact
An unauthenticated attacker can execute arbitrary code on the server, leading to full compromise of confidentiality, integrity and availability. This typically means data theft, webshell deployment and lateral movement into the hosting environment.
Attack surface
Reached over the network via HTTP against the Craft CMS application; the CVSS vector shows no privileges required and no user interaction. No authentication is needed to attempt exploitation.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.942, 99.8th percentile) and public exploit material exists in the Packet Storm reference. That combination indicates active, likely automated exploitation attempts.
What to do
- Upgrade Craft CMS to 4.4.15 or later immediately; apply the referenced patch commits if a full upgrade is not possible.
- If patching is delayed, restrict network access to the Craft admin and front-end endpoints to trusted IPs or place the site behind a WAF.
- Review and harden file permissions and disable unused plugins/modules that expand the attack surface.
- Rotate secrets, database credentials and API keys after patching in case of prior compromise.
- Monitor vendor advisory GHSA-4w8r-3xrw-v25g for any updated guidance.
Detection
- Hunt web logs for POST requests to Craft endpoints with unusual or serialized parameters that precede process execution or file writes.
- Monitor for unexpected child processes spawned by the web server (php-fpm, apache, nginx) and for new files in web-accessible directories.
- Alert on outbound connections from the Craft host to unknown IPs, which may indicate post-exploitation tooling.
- Use file integrity monitoring on Craft application directories to catch webshell drops.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-41892 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-41892), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.