← Back

CVE-2025-23209

nvd nist
Published: Jan 18, 2025Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security key is affected. This vulnerability has been patched in Craft 5.5.8 and 4.13.8. Users who cannot update to a patched version, should rotate their security keys and ensure their privacy to help migitgate the issue.

Affected (8)

Products: Craftcms: Craft Cms
1 product
Craft Cms
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Craftcms
After 4.0.0 to 4.13.8
After 5.0.0 to 5.5.8
Version 4.0.0
Version 4.0.0 rc1
Version 4.0.0 rc2
Version 4.0.0 rc3
Version 5.0.0
Version 5.0.0 rc1

References (4)

Source: security-advisories@github.com
Vendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.