Junglewise Threat Intelligence

CVE-2025-32432: Craft CMS remote code execution via code injection

CVE-2025-32432 · Severity: critical · CVSS 10 · Exploited in the wild · Published 2026-03-20

Technologies: Craft CMS. Vendors: Craft CMS.

Executive brief

Craft CMS, a popular platform for building and managing websites, contains a critical security flaw that allows unauthorized individuals to take complete control of the server. This vulnerability is currently being exploited by attackers in the wild, posing a severe risk to website availability and sensitive customer data. Organizations using affected versions should update immediately to prevent potential ransomware or data theft.

Technical details

Craft CMS is vulnerable to remote code execution (RCE) due to improper control of code generation (CWE-94). The vulnerability allows a remote, unauthenticated attacker to inject and execute arbitrary code on the underlying server with high impact and low complexity. This issue is noted as an additional fix for the previous CVE-2023-41892. CISA has confirmed active exploitation in the wild. Patches are available in versions 3.9.15, 4.14.15, and 5.6.17.

Affected products

  • Craft CMS Craft CMS 3.0.0-RC1 to < 3.9.15, 4.0.0-RC1 to < 4.14.15, 5.0.0-RC1 to < 5.6.17

Timeline

  • 2025-04-10: patched: Vendor released patches across major versions 3.x, 4.x, and 5.x.
  • 2025-04-25: disclosed: Initial CVE publication.
  • 2026-03-20: kev added: CISA added the vulnerability to the Known Exploited Vulnerabilities (KEV) catalog.

Related threats