Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.
🚨 Marked as known exploited on April 26th, 2025 (about 1 month ago).
CVE ID: CVE-2025-32432
CVSS Base Severity: CRITICAL
CVSS Base Score: 10.0
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Vendor: craftcms
Product: cms
http/cves/2025/CVE-2025-32432.yaml
EPSS Score: 76.27% (probability of being exploited)
EPSS Percentile: 98.85% (scored less or equal to compared to others)
EPSS Date: 2025-05-24 (when was this score calculated)
SSVC Exploitation: none
SSVC Technical Impact: total
SSVC Automatable: true