← Vulnerability feed

Vulnerability record · CVE-2025-23209 · published 18 January 2025

CVE-2025-23209: Craft CMS code injection RCE with compromised security key

Craftcms · Craft Cms

Craft CMS 4 and 5 contain a code injection flaw (CWE-94) that allows remote code execution when the installation's security key has already been compromised. The vendor patched it in Craft 5.5.8 and 4.13.8. Because exploitation requires a pre-existing key compromise, the flaw is a post-compromise escalation path rather than a standalone entry point.

8.1 CVSS 3.1 High CISA KEV since 20 Feb 2025 EPSS 22% · top 2.4% CWE-94 · Code injection
8.1CVSS 3.1 base score
22%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security key is affected. This vulnerability has been patched in Craft 5.5.8 and 4.13.8. Users who cannot update to a patched version, should rotate their security keys and ensure their privacy to help migitgate the issue.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is a remote code execution flaw listed in CISA KEV with a high EPSS percentile, and exploitation leads to full host compromise.

What it is

Craft CMS 4 and 5 contain a code injection flaw (CWE-94) that allows remote code execution when the installation's security key has already been compromised. The vendor patched it in Craft 5.5.8 and 4.13.8. Because exploitation requires a pre-existing key compromise, the flaw is a post-compromise escalation path rather than a standalone entry point.

Impact

An attacker who holds the compromised security key can execute arbitrary code on the Craft server, gaining full control of the application and its data. This can lead to data theft, defacement, or use of the host as a pivot point.

Attack surface

Reachable over the network (AV:N) with no authentication or user interaction required per the CVSS vector, but only when the security key is already compromised. The precondition is key exposure, not a weakness in the request path itself.

Exploitation

CVE-2025-23209 was added to CISA KEV on 2025-02-20 with a remediation due date of 2025-03-13, indicating known exploitation in the wild. EPSS gives a 30-day probability of 0.21776 (97.5th percentile), and no ransomware campaign use is documented.

What to do

  • Upgrade to Craft CMS 5.5.8 or 4.13.8 immediately.
  • If patching is not possible, rotate the security key and verify it has not been exposed.
  • Audit for prior security key compromise and treat any exposed key as a breach indicator.
  • Restrict network access to Craft admin and application endpoints where feasible.
  • Monitor vendor advisories and CISA KEV for updated guidance.

Detection

  • Search application and web server logs for unexpected code execution or anomalous requests around Craft endpoints.
  • Alert on changes to Craft configuration files or the security key value.
  • Hunt for signs of security key exposure in repositories, logs, or backups.
  • Correlate host-level process creation events with Craft PHP worker activity for suspicious child processes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-23209 to the Known Exploited Vulnerabilities catalog on 20 February 2025 as "Craft CMS Code Injection Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 13 March 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-23209 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32432Craft CMS unauthenticated remote code execution via code injectionCraft CMS versions 3.0.0-RC1 through 3.9.14, 4.0.0-RC1 through 4.14.14, and 5.0.0-RC1 through 5.6.16 contain a code injection flaw enabling remote co…KEVEPSS 100%analysed9.3CVE-2024-56145Craft CMS code injection via register_argc_argv leads to RCECraft CMS contains a code injection flaw (CWE-94) that allows remote code execution when the PHP setting register_argc_argv is enabled. The vendor de…KEVEPSS 97%analysed6.9CVE-2025-35939Craft CMS unauthenticated session file write enables PHP code injectionCraft CMS stores unsanitized client-supplied return URL values in server-side session files for unauthenticated users. Because the session file path …KEVEPSS 1.3%analysed9.8CVE-2024-37843Craft CMS SQL injection via GraphQL API endpointCraft CMS up to v3.7.31 contains a SQL injection flaw reachable through its GraphQL API endpoint. The CVSS vector indicates the attack is network-rea…EPSS 53%analysed9.8CVE-2023-41892Craft CMS code injection enables unauthenticated remote code executionCraft CMS versions before 4.4.15 contain a code injection flaw (CWE-94) that allows remote code execution. The vendor describes it as a high-impact, …EPSS 94%analysed9.8CVE-2021-27903Craftcms craft cms missing authorization vulnerabilityAn issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did n…EPSS 2.8%9.8CVE-2020-9757SEOmatic for Craft CMS template injection leads to RCEThe SEOmatic component for Craft CMS before 3.3.0 is vulnerable to server-side template injection through malformed data sent to the metacontainers c…EPSS 73%analysed9.8CVE-2019-15929Craftcms craft cms weak password recovery vulnerabilityIn Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a …EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2025-23209), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.