Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.
CVE-2025-32432
Score elevated to 10.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2026-03-20), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 10.0 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 10.0
- EG Score
- 10.0(high)
- EG Risk
- 100(Act)EG Risk 100/100SSVC: Act
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity100% × 45%Exploitation100% × 40%Automatability100% × 15%Action: Fix now — active exploitation, automatable, high impact. - EPSS PROB
- 100%
- EPSS %ILE
- 100%
- KEV
- ⚠ Exploited
Published
April 25, 2025
Last Modified
March 20, 2026
Advisory Details (7)
Auto-updated Aug 1, 2026Known Exploited Vulnerabilities Catalog | CISA
Known Exploited Vulnerabilities Catalog | CISA. Listed in CISA Known Exploited Vulnerabilities catalog.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32432SensePost | Investigating an in-the-wild campaign using RCE in CraftCMS
https://sensepost.com/blog/2025/investigating-an-in-the-wild-campaign-using-rce-in-craftcms/Remote Code Execution · Advisory · craftcms/cms · GitHub
https://github.com/craftcms/cms/security/advisories/GHSA-f3gw-9ww9-jmc3commit e1c85441fa47 (craftcms/cms)
Patch available: craftcms/cms 6.0.0-alpha.3 (contains commit e1c85441fa47)
https://github.com/craftcms/cms/commit/e1c85441fa47eeb7c688c2053f25419bc0547b47cms/CHANGELOG.md at 5.x · craftcms/cms · GitHub
https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5617---2025-04-10-criticalcms/CHANGELOG.md at 4.x · craftcms/cms · GitHub
https://github.com/craftcms/cms/blob/4.x/CHANGELOG.md#41415---2025-04-10-criticalcms/CHANGELOG.md at 3.x · craftcms/cms · GitHub
https://github.com/craftcms/cms/blob/3.x/CHANGELOG.md#3915---2025-04-10-criticalAffected Packages
(1 across 1 ecosystem)
Packagist(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| craftcms/cms | 5.0.0 ... 5.6.9.1 (101 versions) | 5.6.17 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 8× in last 7d / 39× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-08-07 17:09 UTCCISA KEV update
- 2026-08-06 14:01 UTCEG score recompute
- 2026-08-06 13:46 UTCEPSS rescore
- 2026-08-05 17:25 UTCCISA KEV update
- 2026-08-04 17:02 UTCCISA KEV update
- 2026-08-04 16:37 UTCEG score recompute
- 2026-08-04 15:09 UTCEPSS rescore
- 2026-08-03 19:22 UTCCISA KEV update
- 2026-07-30 11:52 UTCEG score recompute
- 2026-07-30 04:19 UTCEG score recompute
- 2026-07-30 01:29 UTCEPSS rescore
- 2026-07-29 19:27 UTCCISA KEV update
- 2026-07-27 19:24 UTCCISA KEV update
- 2026-07-27 17:17 UTCCISA KEV update
- 2026-07-27 15:42 UTCEG score recompute
- 2026-07-27 14:12 UTCEPSS rescore
- 2026-07-26 16:58 UTCEG score recompute
- 2026-07-26 14:53 UTCEPSS rescore
- 2026-07-26 13:10 UTCEG score recompute
- 2026-07-26 01:48 UTCEG score recompute
- 2026-07-24 14:17 UTCEPSS rescore
- 2026-07-23 02:53 UTCEG score recompute
- 2026-07-22 22:05 UTCEG score recompute
- 2026-07-22 19:40 UTCCISA KEV update
- 2026-07-22 14:30 UTCEG score recompute
Show 52 moreShow fewer
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-18 10:51 UTCEG score recompute
- 2026-07-18 10:04 UTCEPSS rescore
- 2026-07-18 10:04 UTCEPSS rescore
- 2026-07-17 08:26 UTCEG score recompute
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-16 17:02 UTCEPSS rescore
- 2026-07-15 16:49 UTCCISA KEV update
- 2026-07-15 15:04 UTCCISA KEV update
- 2026-07-14 18:05 UTCCISA KEV update
- 2026-07-13 17:07 UTCCISA KEV update
- 2026-07-10 17:52 UTCCISA KEV update
- 2026-07-07 19:01 UTCCISA KEV update
- 2026-07-07 17:16 UTCCISA KEV update
- 2026-07-06 16:27 UTCEPSS rescore
- 2026-07-06 16:26 UTCEPSS rescore
- 2026-07-01 19:16 UTCCISA KEV update
- 2026-06-29 19:12 UTCCISA KEV update
- 2026-06-25 19:15 UTCCISA KEV update
- 2026-06-25 13:49 UTCEPSS rescore
- 2026-06-25 13:49 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-23 17:44 UTCCISA KEV update
- 2026-06-18 16:13 UTCCISA KEV update
- 2026-06-16 19:33 UTCCISA KEV update
- 2026-06-15 19:33 UTCCISA KEV update
- 2026-06-15 17:48 UTCEPSS rescore
- 2026-06-14 23:17 UTCEPSS rescore
- 2026-06-12 17:35 UTCCISA KEV update
- 2026-06-11 19:10 UTCCISA KEV update
- 2026-06-09 18:42 UTCCISA KEV update
- 2026-06-09 17:12 UTCCISA KEV update
- 2026-06-08 19:16 UTCCISA KEV update
- 2026-06-08 17:26 UTCCISA KEV update
- 2026-06-08 14:16 UTCEPSS rescore
- 2026-06-08 14:16 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 22:43 UTCCISA KEV update
- 2026-06-04 13:12 UTCEPSS rescore
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-03 19:09 UTCCISA KEV update
- 2026-06-02 18:32 UTCCISA KEV update
- 2026-06-01 20:42 UTCCISA KEV update
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-29 22:23 UTCEG score recompute
- 2026-05-29 22:20 UTCCISA KEV update
- 2026-05-29 13:44 UTCEPSS rescore
Publicly available exploits
(9 references)Working exploit code is in the public domain (1 Metasploit module) (6 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCc0gnit00/CVE-2025-32432First seen Jul 21, 2026
Exploit, POC for CVE-2025-32432, CraftCMS2Shell
Open source ↗ - GitHub PoCcd-ratel/CVE-2025-32432First seen May 15, 2026
Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning
Open source ↗ - Exploit-DBEDB-52525First seen Apr 29, 2026
Craft CMS 5.6.16 - RCE
Open source ↗ - GitHub PoCbambooqj/CVE-2025-32432First seen Sep 23, 2025
AI修复生成的CVE-2025-32432的poc
Open source ↗ - Open source ↗GitHub PoCCTY-Research-1/CVE-2025-32432-PoCFirst seen Jun 1, 2025
- GitHub PoCSachinart/CVE-2025-32432First seen Apr 27, 2025
This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability affecting CraftCMS versions 4.x and 5.x. The vulnerability exists in the asset transform generation feature of CraftCMS.
Open source ↗ - GitHub PoCChocapikk/CVE-2025-32432First seen Apr 26, 2025
CraftCMS RCE Checker (CVE-2025-32432)
Open source ↗ - Metasploitexploit/linux/http/craftcms_preauth_rce_cve_2025_32432✓ verifiedFirst seen Apr 14, 2025
Craft CMS Image Transform Preauth RCE (CVE-2025-32432)
Open source ↗ - Nucleihttp/cves/2025/CVE-2025-32432.yamlFirst seen Jan 1, 2025
CraftCMS - Remote Code Execution
Open source ↗
Related CVEs(same CWE)
Same CWE
10 shownCWE-94
- CVE-2003-1432EG 10.0EPSS p94HIGH
- CVE-2002-0495EG 10.0EPSS p96HIGH
- CVE-1999-0702EG 10.0EPSS p98HIGH
- CVE-1999-0509EG 10.0EPSS p98HIGH
- CVE-2006-1318EG 9.3EPSS p96HIGH
- CVE-2006-1301EG 9.3EPSS p95HIGH
- CVE-2006-1308EG 9.3EPSS p95HIGH
- CVE-2006-1309EG 9.3EPSS p95HIGH
- CVE-2006-1304EG 9.3EPSS p95HIGH
- CVE-2006-1306EG 9.3EPSS p95HIGH
Frequently asked(6)
What is CVE-2025-32432?
When was CVE-2025-32432 disclosed?
Is CVE-2025-32432 actively exploited?
What is the CVSS score of CVE-2025-32432?
Which products are affected by CVE-2025-32432?
How do I remediate CVE-2025-32432?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2025-32432
Is Your Infrastructure Affected by CVE-2025-32432?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.