Remote Code Execution Vulnerability in Craft CMS by Pixel & Tonic
CVE-2025-32432

10CRITICAL

Key Information:

Vendor
Craftcms
Status
Vendor
CVE Published:
25 April 2025

Badges

📈 Score: 1,800💰 Ransomware👾 Exploit Exists🟣 EPSS 67%📰 News Worthy

What is CVE-2025-32432?

CVE-2025-32432 is a high-severity remote code execution vulnerability found in Craft CMS, a flexible content management system designed for creating custom digital experiences. This vulnerability affects specific versions of the software, enabling malicious actors to execute arbitrary code on affected installations. Organizations using Craft CMS could face considerable risks, including unauthorized data access, system compromise, and disruption of services, directly impacting their operational integrity and reputation.

Technical Details

The vulnerability exists in Craft CMS starting from version 3.0.0-RC1 up to, but not including, version 3.9.15, as well as from version 4.0.0-RC1 to before 4.14.15 and from 5.0.0-RC1 to prior to 5.6.17. Exploitation involves a low-complexity attack vector, making it relatively easy for attackers to implement. The issue has been addressed in patched versions 3.9.15, 4.14.15, and 5.6.17, along with a fix for a previously identified vulnerability (CVE-2023-41892).

Potential Impact of CVE-2025-32432

  1. Unauthorized Access and Control: Attackers can gain unauthorized access to the system, potentially leading to the execution of arbitrary commands and loss of sensitive information.

  2. Service Disruption: Exploiting this vulnerability can lead to service outages, disrupting business operations and affecting user experience.

  3. Increased Risk of Data Breaches: Vulnerable systems may be targeted for data breaches, exposing sensitive data to unauthorized entities and resulting in significant reputational damage and regulatory consequences for affected organizations.

Affected Version(s)

cms >= 3.0.0-RC1, < 3.9.15 < 3.0.0-RC1, 3.9.15

cms >= 4.0.0-RC1, < 4.14.15 < 4.0.0-RC1, 4.14.15

cms >= 5.0.0-RC1, < 5.6.17 < 5.0.0-RC1, 5.6.17

News Articles

Critical Craft CMS Flaws Exploited in Wild

Craft CMS flaws CVE-2025-32432 and CVE-2024-58136 are under active attack. Over 300 servers breached—patch your sites now to avoid compromise.

2 weeks ago

Attackers chained Craft CMS zero-days attacks in the wild

Orange Cyberdefense's CSIRT reported that threat actors exploited two vulnerabilities in Craft CMS to breach servers and steal data.

2 weeks ago

Hackers Exploit Critical Craft CMS Flaws; Hundreds of Servers Likely Compromised

Threat actors exploited Craft CMS zero-days CVE-2025-32432 and CVE-2024-58136, compromising 300 of 13,000 vulnerable servers.

2 weeks ago

References

EPSS Score

67% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • 💰

    Used in Ransomware

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by BleepingComputer

  • Vulnerability published

.