High severity8.0CISA KEVNVD Advisory· Published Jan 18, 2025· Updated Jun 17, 2026
CVE-2025-23209
CVE-2025-23209
Description
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security key is affected. This vulnerability has been patched in Craft 5.5.8 and 4.13.8. Users who cannot update to a patched version, should rotate their security keys and ensure their privacy to help migitgate the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
craftcms/cmsPackagist | >= 5.0.0-RC1, < 5.5.8 | 5.5.8 |
craftcms/cmsPackagist | >= 4.0.0-RC1, < 4.13.8 | 4.13.8 |
Affected products
9cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:*range: >4.0.0,<4.13.8
- cpe:2.3:a:craftcms:craft_cms:4.0.0:-:*:*:*:*:*:*
- cpe:2.3:a:craftcms:craft_cms:4.0.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:craftcms:craft_cms:4.0.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:craftcms:craft_cms:4.0.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:craftcms:craft_cms:5.0.0:-:*:*:*:*:*:*
- cpe:2.3:a:craftcms:craft_cms:5.0.0:rc1:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- github.com/craftcms/cms/commit/e59e22b30c9dd39e5e2c7fe02c147bcbd004e603nvdPatchWEB
- github.com/advisories/GHSA-x684-96hh-833xghsaADVISORY
- github.com/craftcms/cms/security/advisories/GHSA-x684-96hh-833xnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-23209ghsaADVISORY
- craftcms.com/knowledge-base/securing-craftnvdProductWEB
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government ResourceWEB
News mentions
0No linked articles in our index yet.