FAIL › dossier
Craft CMS
VENDOR· dossier confidence 50%
Craft CMS, a popular open-source CMS, has faced multiple high-severity vulnerabilities, including remote code execution, compromising the security of websites using the platform.
PROFILE
CategoryContent Management SystemWhat they doCraft CMS is an open-source content management system (CMS) for publishing digital content on websites. It is designed to simplify the process of building websites, particularly for individuals without formal training in web development.
SECURITY POSTURE
Craft CMS has a history of high-severity security vulnerabilities, including remote code execution (RCE) and external control of assumed-immutable web parameters.
Notable failures
- CVE-2025-23209 (high [RCE])
- CVE-2025-32432 (high [RCE])
- CVE-2024-56145 (high [RCE])
- CVE-2025-35939 (high)
Patterns: Repeated code injection vulnerabilities; Improper validation leading to RCE
FAILURE HISTORY · 8
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-06-02 | CVE-2025-35939 | high | Craft CMS exposed RCE, allowing unauthenticated attackers to execute arbitrary PHP code on servers hosting the platform. |
| 2025-06-02 | CVE-2025-35939 | high | Craft CMS exposed RCE, allowing unauthenticated attackers to execute arbitrary PHP code on servers hosting the platform. |
| 2026-03-20 | CVE-2025-32432 | high | Craft CMS allows remote attackers to execute arbitrary code via a code injection vulnerability. |
| 2026-03-20 | CVE-2025-32432 | high | Craft CMS allows remote attackers to execute arbitrary code via a code injection vulnerability. |
| 2025-06-02 | CVE-2024-56145 | high | Craft CMS RCE due to unpatched php.ini configuration |
| 2025-06-02 | CVE-2024-56145 | high | Craft CMS RCE due to unpatched php.ini configuration |
| 2025-02-20 | CVE-2025-23209 | high | Craft CMS's improper backup path validation allowed remote code execution, actively exploited in the wild. |
| 2025-02-20 | CVE-2025-23209 | high | Craft CMS's improper backup path validation allowed remote code execution, actively exploited in the wild. |
Open questions: How has Craft CMS addressed these vulnerabilities? · What is the current security posture of Craft CMS?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-25 03:46:33.810704+00:00