EXPOSURES › CVE-2025-35939
CVE-2025-35939
HIGH ⌖ ON CISA KEV · EXPLOITEDCraft CMS exposed RCE, allowing unauthenticated attackers to execute arbitrary PHP code on servers hosting the platform.
Craft CMS suffered a high-severity vulnerability that enabled remote code execution, potentially allowing attackers to compromise websites using the CMS without authentication. This exposed the platform to significant security risks, including unauthorized access and data breaches.
Shame score — Craft CMS's high-severity RCE vulnerability exposed numerous websites to unauthorized code execution, leading to potential data breaches and unauthorized access.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulnerability could allow an unauthenticated client to introduce arbitrary values, such as PHP code, to a known local file location on the server. This vulnerability could be chained with CVE-2024-58136 as represented by CVE-2025-32432.