Skip to content
COOEY

FAIL › dossier

Craft CMS

VENDOR

· dossier confidence 50%

Craft CMS, a popular open-source CMS, has faced multiple high-severity vulnerabilities, including remote code execution, compromising the security of websites using the platform.

PROFILE
CategoryContent Management SystemWhat they doCraft CMS is an open-source content management system (CMS) for publishing digital content on websites. It is designed to simplify the process of building websites, particularly for individuals without formal training in web development.
SECURITY POSTURE

Craft CMS has a history of high-severity security vulnerabilities, including remote code execution (RCE) and external control of assumed-immutable web parameters.

Notable failures
  • CVE-2025-23209 (high [RCE])
  • CVE-2025-32432 (high [RCE])
  • CVE-2024-56145 (high [RCE])
  • CVE-2025-35939 (high)
Patterns: Repeated code injection vulnerabilities; Improper validation leading to RCE
FAILURE HISTORY · 8
DATEEVENTSEVSUMMARY
2025-06-02 CVE-2025-35939 high Craft CMS exposed RCE, allowing unauthenticated attackers to execute arbitrary PHP code on servers hosting the platform.
2025-06-02 CVE-2025-35939 high Craft CMS exposed RCE, allowing unauthenticated attackers to execute arbitrary PHP code on servers hosting the platform.
2026-03-20 CVE-2025-32432 high Craft CMS allows remote attackers to execute arbitrary code via a code injection vulnerability.
2026-03-20 CVE-2025-32432 high Craft CMS allows remote attackers to execute arbitrary code via a code injection vulnerability.
2025-06-02 CVE-2024-56145 high Craft CMS RCE due to unpatched php.ini configuration
2025-06-02 CVE-2024-56145 high Craft CMS RCE due to unpatched php.ini configuration
2025-02-20 CVE-2025-23209 high Craft CMS's improper backup path validation allowed remote code execution, actively exploited in the wild.
2025-02-20 CVE-2025-23209 high Craft CMS's improper backup path validation allowed remote code execution, actively exploited in the wild.
Open questions: How has Craft CMS addressed these vulnerabilities? · What is the current security posture of Craft CMS?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-25 03:46:33.810704+00:00