Junglewise Threat Intelligence

CVE-2025-23209: Craft CMS has a potential RCE with a compromised security key

CVE-2025-23209 · Severity: critical · CVSS 3.1 · Exploited in the wild · Published 2025-01-21

Technologies: Craft CMS. Vendors: Craft CMS.

Executive brief

Craft CMS contains a code injection vulnerability due to improper validation of the database backup path. This allows remote code execution (RCE) on systems where the security key has been compromised.

Affected products

  • Craft CMS Craft CMS 4.x < 4.13.8, 5.x < 5.5.8

Timeline

  • 2025-01-17: disclosed
  • 2025-02-20: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-02-20: exploited
  • 2025-01-17: patched: Patched in versions 4.13.8 and 5.5.8

Related threats