Vulnerability Details
Basic Information
| Title | CVE-2025-32432 Craft CMS Allows Remote Code Execution |
|---|---|
| Type | cvelist |
| Published | 2025-04-25T15:04:06 |
| Last Seen | 2025-04-25T16:07:42 |
| CVSS Score | 10.0 (CRITICAL) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | NONE |
| User Interaction | NONE |
| Scope | CHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | LOW |
CVE Information
| CVE IDs | CVE-2023-41892, CVE-2025-32432 |
|---|---|
| CWE | CWE-94 |
| Bulletin Family | cve |
Description
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.
Impact Assessment
| Base Score | 10.0 |
|---|---|
| Severity | CRITICAL |