VYPR
Critical severityCISA KEVNVD Advisory· Published Apr 25, 2025· Updated Mar 21, 2026

Craft CMS Allows Remote Code Execution

CVE-2025-32432

Description

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
craftcms/cmsPackagist
>= 3.0.0-RC1, < 3.9.153.9.15
craftcms/cmsPackagist
>= 4.0.0-RC1, < 4.14.154.14.15
craftcms/cmsPackagist
>= 5.0.0-RC1, < 5.6.175.6.17

Affected products

2

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.