Vulnerability record · CVE-2025-32432 · published 25 April 2025
CVE-2025-32432: Craft CMS unauthenticated remote code execution via code injection
Craftcms · Craft Cms
Craft CMS versions 3.0.0-RC1 through 3.9.14, 4.0.0-RC1 through 4.14.14, and 5.0.0-RC1 through 5.6.16 contain a code injection flaw enabling remote code execution. It is a follow-up fix to CVE-2023-41892, meaning the earlier patch was incomplete. With a CVSS score of 10.0 and no privileges or user interaction required, it is a severe exposure for any unpatched public-facing Craft install.
Description
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 10.0, unauthenticated network RCE, confirmed in-the-wild exploitation, and KEV listing with a near-certain EPSS score make this an emergency patch.
What it is
Craft CMS versions 3.0.0-RC1 through 3.9.14, 4.0.0-RC1 through 4.14.14, and 5.0.0-RC1 through 5.6.16 contain a code injection flaw enabling remote code execution. It is a follow-up fix to CVE-2023-41892, meaning the earlier patch was incomplete. With a CVSS score of 10.0 and no privileges or user interaction required, it is a severe exposure for any unpatched public-facing Craft install.
Impact
An unauthenticated attacker can execute arbitrary code on the server, leading to full compromise of the CMS and potentially the underlying host. This enables data theft, defacement, persistence, and lateral movement into connected systems.
Attack surface
Reachable over the network via HTTP against the Craft CMS web application, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required, so any internet-exposed instance is directly targetable.
Exploitation
CISA added it to the KEV catalog with a due date of 2026-04-03, and EPSS shows a 30-day probability of 0.99837 (99.96th percentile). A reference tagged Exploit and Press/Media Coverage describes an in-the-wild campaign, so active exploitation is confirmed.
What to do
- Upgrade Craft CMS to 3.9.15, 4.14.15, or 5.6.17 immediately; these versions contain the patch.
- If immediate upgrade is not possible, apply vendor mitigations per the Craft security advisory or take the instance offline until patched.
- Restrict network access to the Craft admin and front-end endpoints to trusted sources where feasible.
- Rotate secrets, database credentials, and API keys on any instance that may have been exposed, and review for unauthorized admin accounts or scheduled tasks.
- Monitor CISA KEV guidance and BOD 22-01 requirements for cloud-hosted instances.
Detection
- Search web and application logs for unusual POST requests or parameters targeting Craft endpoints, especially patterns associated with the prior CVE-2023-41892 exploit chain.
- Monitor for unexpected child processes spawned by the web server or PHP-FPM (for example shells, curl, or wget).
- Audit Craft CMS file system and database for newly created or modified PHP files, plugins, or scheduled tasks outside normal change windows.
- Alert on outbound network connections from the Craft host to unfamiliar IPs or domains.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-32432 to the Known Exploited Vulnerabilities catalog on 20 March 2026 as "Craft CMS Code Injection Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 3 April 2026.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/craftcms/cms/blob/3.x/CHANGELOG.md#3915---2025-04-10-critical | ProductRelease Notes |
| https://github.com/craftcms/cms/blob/4.x/CHANGELOG.md#41415---2025-04-10-critical | ProductRelease Notes |
| https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5617---2025-04-10-critical | ProductRelease Notes |
| https://github.com/craftcms/cms/commit/e1c85441fa47eeb7c688c2053f25419bc0547b47 | Patch |
| https://github.com/craftcms/cms/security/advisories/GHSA-f3gw-9ww9-jmc3 | Vendor Advisory |
| https://sensepost.com/blog/2025/investigating-an-in-the-wild-campaign-using-rce-in-craftcms/ | ExploitPress/Media Coverage |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32432 | US Government Resource |
Track CVE-2025-32432 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-32432), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.