Metrics
Affected Vendors & Products
Mon, 28 Apr 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Craftcms
Craftcms craft Cms |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* | |
Vendors & Products |
Craftcms
Craftcms craft Cms |
Fri, 25 Apr 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
ssvc
|
ssvc
|
Fri, 25 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 25 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892. | |
Title | Craft CMS Allows Remote Code Execution | |
Weaknesses | CWE-94 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-04-25T15:04:06.272Z
Updated: 2025-04-29T03:55:14.713Z
Reserved: 2025-04-08T10:54:58.368Z
Link: CVE-2025-32432

Updated: 2025-04-25T15:25:48.950Z

Status : Analyzed
Published: 2025-04-25T15:15:36.440
Modified: 2025-04-28T20:57:06.397
Link: CVE-2025-32432

No data.