Known vulnerability record

CVE-2025-32432

Craft CMS Code Injection Vulnerability

Stable IDcve:CVE-2025-32432Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

Craft CMS Code Injection Vulnerability

Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.

Keep the signals separate

CVSS severitycriticalScore 10 · source GitHub_M
EPSS probability99.8%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2026-03-20
Ransomware useunknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2025-04-25
CVE modified
2026-03-21
KEV date added
2026-03-20
Dataset fetched
2026-08-21T03:55:06.086Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.