← Vulnerability feed

Vulnerability record · CVE-2025-32432 · published 25 April 2025

CVE-2025-32432: Craft CMS unauthenticated remote code execution via code injection

Craftcms · Craft Cms

Craft CMS versions 3.0.0-RC1 through 3.9.14, 4.0.0-RC1 through 4.14.14, and 5.0.0-RC1 through 5.6.16 contain a code injection flaw enabling remote code execution. It is a follow-up fix to CVE-2023-41892, meaning the earlier patch was incomplete. With a CVSS score of 10.0 and no privileges or user interaction required, it is a severe exposure for any unpatched public-facing Craft install.

10.0 CVSS 3.1 Critical CISA KEV since 20 Mar 2026 EPSS 100% · top 0.1% CWE-94 · Code injection
10.0CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 1 tagged exploit
24 Sep 2026Last modified by NVD

Description

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 10.0, unauthenticated network RCE, confirmed in-the-wild exploitation, and KEV listing with a near-certain EPSS score make this an emergency patch.

What it is

Craft CMS versions 3.0.0-RC1 through 3.9.14, 4.0.0-RC1 through 4.14.14, and 5.0.0-RC1 through 5.6.16 contain a code injection flaw enabling remote code execution. It is a follow-up fix to CVE-2023-41892, meaning the earlier patch was incomplete. With a CVSS score of 10.0 and no privileges or user interaction required, it is a severe exposure for any unpatched public-facing Craft install.

Impact

An unauthenticated attacker can execute arbitrary code on the server, leading to full compromise of the CMS and potentially the underlying host. This enables data theft, defacement, persistence, and lateral movement into connected systems.

Attack surface

Reachable over the network via HTTP against the Craft CMS web application, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required, so any internet-exposed instance is directly targetable.

Exploitation

CISA added it to the KEV catalog with a due date of 2026-04-03, and EPSS shows a 30-day probability of 0.99837 (99.96th percentile). A reference tagged Exploit and Press/Media Coverage describes an in-the-wild campaign, so active exploitation is confirmed.

What to do

  • Upgrade Craft CMS to 3.9.15, 4.14.15, or 5.6.17 immediately; these versions contain the patch.
  • If immediate upgrade is not possible, apply vendor mitigations per the Craft security advisory or take the instance offline until patched.
  • Restrict network access to the Craft admin and front-end endpoints to trusted sources where feasible.
  • Rotate secrets, database credentials, and API keys on any instance that may have been exposed, and review for unauthorized admin accounts or scheduled tasks.
  • Monitor CISA KEV guidance and BOD 22-01 requirements for cloud-hosted instances.

Detection

  • Search web and application logs for unusual POST requests or parameters targeting Craft endpoints, especially patterns associated with the prior CVE-2023-41892 exploit chain.
  • Monitor for unexpected child processes spawned by the web server or PHP-FPM (for example shells, curl, or wget).
  • Audit Craft CMS file system and database for newly created or modified PHP files, plugins, or scheduled tasks outside normal change windows.
  • Alert on outbound network connections from the Craft host to unfamiliar IPs or domains.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-32432 to the Known Exploited Vulnerabilities catalog on 20 March 2026 as "Craft CMS Code Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 3 April 2026.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-32432 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2024-56145Craft CMS code injection via register_argc_argv leads to RCECraft CMS contains a code injection flaw (CWE-94) that allows remote code execution when the PHP setting register_argc_argv is enabled. The vendor de…KEVEPSS 97%analysed8.1CVE-2025-23209Craft CMS code injection RCE with compromised security keyCraft CMS 4 and 5 contain a code injection flaw (CWE-94) that allows remote code execution when the installation's security key has already been comp…KEVEPSS 22%analysed6.9CVE-2025-35939Craft CMS unauthenticated session file write enables PHP code injectionCraft CMS stores unsanitized client-supplied return URL values in server-side session files for unauthenticated users. Because the session file path …KEVEPSS 1.3%analysed9.8CVE-2024-37843Craft CMS SQL injection via GraphQL API endpointCraft CMS up to v3.7.31 contains a SQL injection flaw reachable through its GraphQL API endpoint. The CVSS vector indicates the attack is network-rea…EPSS 53%analysed9.8CVE-2023-41892Craft CMS code injection enables unauthenticated remote code executionCraft CMS versions before 4.4.15 contain a code injection flaw (CWE-94) that allows remote code execution. The vendor describes it as a high-impact, …EPSS 94%analysed9.8CVE-2021-27903Craftcms craft cms missing authorization vulnerabilityAn issue was discovered in Craft CMS before 3.6.7. In some circumstances, a potential Remote Code Execution vulnerability existed on sites that did n…EPSS 2.8%9.8CVE-2020-9757SEOmatic for Craft CMS template injection leads to RCEThe SEOmatic component for Craft CMS before 3.3.0 is vulnerable to server-side template injection through malformed data sent to the metacontainers c…EPSS 73%analysed9.8CVE-2019-15929Craftcms craft cms weak password recovery vulnerabilityIn Craft CMS through 3.1.7, the elevated session password prompt was not being rate limited like normal login forms, leading to the possibility of a …EPSS 1.8%

Source: NIST National Vulnerability Database (record CVE-2025-32432), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.