← Vulnerability feed

Vulnerability record · CVE-2023-41892 · published 13 September 2023

CVE-2023-41892: Craft CMS code injection enables unauthenticated remote code execution

Craftcms · Craft Cms

Craft CMS versions before 4.4.15 contain a code injection flaw (CWE-94) that allows remote code execution. The vendor describes it as a high-impact, low-complexity attack vector and fixed it in 4.4.15. Because it is network-reachable and needs no credentials, any exposed Craft install is at serious risk.

9.8 CVSS 3.1 Critical EPSS 94% · top 0.2% CWE-94 · Code injection
9.8CVSS 3.1 base score
94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
17 Jun 2026Last modified by NVD

Description

Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, plus very high EPSS and public exploit code, makes this an urgent patch-first issue.

What it is

Craft CMS versions before 4.4.15 contain a code injection flaw (CWE-94) that allows remote code execution. The vendor describes it as a high-impact, low-complexity attack vector and fixed it in 4.4.15. Because it is network-reachable and needs no credentials, any exposed Craft install is at serious risk.

Impact

An unauthenticated attacker can execute arbitrary code on the server, leading to full compromise of confidentiality, integrity and availability. This typically means data theft, webshell deployment and lateral movement into the hosting environment.

Attack surface

Reached over the network via HTTP against the Craft CMS application; the CVSS vector shows no privileges required and no user interaction. No authentication is needed to attempt exploitation.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.942, 99.8th percentile) and public exploit material exists in the Packet Storm reference. That combination indicates active, likely automated exploitation attempts.

What to do

  • Upgrade Craft CMS to 4.4.15 or later immediately; apply the referenced patch commits if a full upgrade is not possible.
  • If patching is delayed, restrict network access to the Craft admin and front-end endpoints to trusted IPs or place the site behind a WAF.
  • Review and harden file permissions and disable unused plugins/modules that expand the attack surface.
  • Rotate secrets, database credentials and API keys after patching in case of prior compromise.
  • Monitor vendor advisory GHSA-4w8r-3xrw-v25g for any updated guidance.

Detection

  • Hunt web logs for POST requests to Craft endpoints with unusual or serialized parameters that precede process execution or file writes.
  • Monitor for unexpected child processes spawned by the web server (php-fpm, apache, nginx) and for new files in web-accessible directories.
  • Alert on outbound connections from the Craft host to unknown IPs, which may indicate post-exploitation tooling.
  • Use file integrity monitoring on Craft application directories to catch webshell drops.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-41892 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32432Craft CMS unauthenticated remote code execution via code injectionCraft CMS versions 3.0.0-RC1 through 3.9.14, 4.0.0-RC1 through 4.14.14, and 5.0.0-RC1 through 5.6.16 contain a code injection flaw enabling remote co…KEVEPSS 100%analysed9.3CVE-2024-56145Craft CMS code injection via register_argc_argv leads to RCECraft CMS contains a code injection flaw (CWE-94) that allows remote code execution when the PHP setting register_argc_argv is enabled. The vendor de…KEVEPSS 97%analysed8.1CVE-2025-23209Craft CMS code injection RCE with compromised security keyCraft CMS 4 and 5 contain a code injection flaw (CWE-94) that allows remote code execution when the installation's security key has already been comp…KEVEPSS 22%analysed6.9CVE-2025-35939Craft CMS unauthenticated session file write enables PHP code injectionCraft CMS stores unsanitized client-supplied return URL values in server-side session files for unauthenticated users. Because the session file path …KEVEPSS 1.3%analysed9.8CVE-2024-37843Craft CMS SQL injection via GraphQL API endpointCraft CMS up to v3.7.31 contains a SQL injection flaw reachable through its GraphQL API endpoint. The CVSS vector indicates the attack is network-rea…EPSS 53%analysed9.8CVE-2021-27903Craftcms craft cms missing authorization vulnerabilityAn issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did n…EPSS 2.8%9.8CVE-2020-9757SEOmatic for Craft CMS template injection leads to RCEThe SEOmatic component for Craft CMS before 3.3.0 is vulnerable to server-side template injection through malformed data sent to the metacontainers c…EPSS 73%analysed9.8CVE-2019-15929Craftcms craft cms weak password recovery vulnerabilityIn Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a …EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2023-41892), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.