Remote Code Execution Vulnerability in Craft CMS by Pixel & Tonic
CVE-2025-57811

6.1MEDIUM

Key Information:

Vendor

Craftcms

Status
Vendor
CVE Published:
25 August 2025

What is CVE-2025-57811?

Craft CMS, a widely-used platform for building digital experiences, has been identified to have a remote code execution vulnerability affecting specific versions of its software. This security issue arises from Server-Side Template Injection (SSTI) via Twig templating, enabling attackers to execute arbitrary code on the server. The vulnerability impacts Craft CMS versions from 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6. Users are strongly advised to upgrade to the patched versions 4.16.6 or 5.8.7 to safeguard their systems against potential exploits. More details can be found in the official security advisory.

Affected Version(s)

cms >= 4.0.0-RC1, < 4.16.6 < 4.0.0-RC1, 4.16.6

cms >= 5.0.0-RC1, < 5.8.7 < 5.0.0-RC1, 5.8.7

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-57811 : Remote Code Execution Vulnerability in Craft CMS by Pixel & Tonic