CVE-2025-32432

9.5 CISA KEV

Craft CMS · Craft CMS

Craft CMS is vulnerable to remote code execution due to improper control of code generation. This high-impact, low-complexity flaw allows unauthenticated attackers to execute arbitrary system code.

Executive summary

A critical remote code execution vulnerability in Craft CMS is currently being actively exploited in the wild, posing an immediate threat to server integrity and data confidentiality.

Vulnerability

This is a code injection vulnerability (CWE-94) that permits an unauthenticated attacker to achieve remote code execution on the underlying host. The flaw is triggered via a low-complexity network attack vector that does not require user interaction or pre-existing privileges.

Business impact

With a CVSS score of 9.5, this vulnerability represents an extreme risk to the organization. Successful exploitation grants an attacker full control over the affected server, potentially leading to unauthorized data exfiltration, total system compromise, and the deployment of ransomware or other malicious payloads.

Remediation

Immediate Action: Update Craft CMS installations to version 3.9.15, 4.14.15, or 5.6.17 immediately to apply the necessary security patches.

Proactive Monitoring: Inspect web server logs for suspicious request patterns, particularly those involving unusual file uploads or command execution sequences, and monitor for unauthorized outbound network connections from the CMS host.

Compensating Controls: Deploy a Web Application Firewall with rules configured to detect and block malicious code injection attempts targeting the CMS, though this should be considered a temporary measure until the software is patched.

Exploitation status

Public Exploit Available: Yes, a Metasploit module and ExploitDB entry exist.

Analyst recommendation

Given the confirmed active exploitation and the critical nature of remote code execution, this vulnerability demands immediate attention from all security and IT operations teams. Organizations must prioritize patching the affected Craft CMS instances above all other maintenance tasks to prevent imminent compromise.

More Craft CMS CVEs

Sources