CVE-2025-32432
CRITICAL
10,0
Source: [email protected]
Attack Vector: network
Attack Complexity: low
Privileges Required: none
User Interaction: none
Scope: changed
Confidentiality: high
Integrity: high
Availability: low
Description
AI Translation Available
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,7524
Percentile
1,0th
Updated
EPSS Score Trend (Last 91 Days)
94
Improper Control of Generation of Code ('Code Injection')
DraftCommon Consequences
Security Scopes Affected:
Access Control
Integrity
Confidentiality
Availability
Non-Repudiation
Potential Impacts:
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Execute Unauthorized Code Or Commands
Hide Activities
Applicable Platforms
Languages:
Interpreted
Technologies:
AI/ML
Application
Craft Cms by Craftcms
Version Range Affected
From
4.0.0
(inclusive)
To
4.14.15
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Craft Cms by Craftcms
Version Range Affected
From
3.0.0
(inclusive)
To
3.9.15
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Craft Cms by Craftcms
Version Range Affected
From
5.0.0
(inclusive)
To
5.6.17
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://sensepost.com/blog/2025/investigating-an-in-the-wild-campaign-using-rce…
https://github.com/craftcms/cms/blob/3.x/CHANGELOG.md#3915---2025-04-10-critical
https://github.com/craftcms/cms/blob/4.x/CHANGELOG.md#41415---2025-04-10-critic…
https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5617---2025-04-10-critical
https://github.com/craftcms/cms/commit/e1c85441fa47eeb7c688c2053f25419bc0547b47
https://github.com/craftcms/cms/security/advisories/GHSA-f3gw-9ww9-jmc3