Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This issue has been fixed in Craft CMS 4.4.15.
CVE-2023-41892
Score elevated to 9.8 because EPSS predicts 93% probability of exploitation within the next 30 days (top 0.2% of all CVEs). NVD baseline CVSS 9.8 retained for reference. Confidence: see factors.
- High exploitation likelihood — EPSS 93%
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 9.8
- EG Score
- 9.8(high)
- EG Risk
- —
- EPSS
- 99.8%
- KEV
- Not listed
Published
September 13, 2023
Last Modified
June 17, 2026
Advisory Details (6)
Auto-updated Jun 18, 2026commit 7359d18d4638 (craftcms/cms)
Patch available: craftcms/cms 4.17.13.1 (contains commit 7359d18d4638)
https://github.com/craftcms/cms/commit/7359d18d46389ffac86c2af1e0cd59e37c298857cms/CHANGELOG.md at 5.x · craftcms/cms · GitHub
https://github.com/craftcms/cms/blob/develop/CHANGELOG.md#4415---2023-07-03-criticalRemote Code Execution · Advisory · craftcms/cms · GitHub
https://github.com/craftcms/cms/security/advisories/GHSA-4w8r-3xrw-v25gcommit c0a37e15cc92 (craftcms/cms)
Patch available: craftcms/cms 4.17.13.1 (contains commit c0a37e15cc92)
https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1#diff-47dd43d86f85161944dfcce2e41d31955c4184672d9bd9d82b948c6b01b86476commit c0a37e15cc92 (craftcms/cms)
Patch available: craftcms/cms 4.17.13.1 (contains commit c0a37e15cc92)
https://github.com/craftcms/cms/commit/c0a37e15cc925c473e60e27fe64054993b867ac1commit a270b928f3d3 (craftcms/cms)
Patch available: craftcms/cms 4.17.13.1 (contains commit a270b928f3d3)
https://github.com/craftcms/cms/commit/a270b928f3d34ad3bd953b81c304424edd57355eAffected Packages
(1 across 1 ecosystem)
Packagist(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| craftcms/cms | 4.0.0 ... 4.4.9 (77 versions) | 4.4.15 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 2× in last 7d / 14× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-22 23:12 UTCEG score recompute▼ 0.20
- 2026-07-19 14:29 UTCEPSS rescore
- 2026-07-15 09:49 UTCOSV refresh
- 2026-07-15 01:58 UTCEPSS rescore
- 2026-06-30 23:21 UTCEPSS rescore
- 2026-06-30 23:21 UTCEPSS rescore
- 2026-06-28 14:06 UTCEPSS rescore
- 2026-06-28 14:06 UTCEPSS rescore
- 2026-06-27 10:34 UTCOSV refresh
- 2026-06-27 03:07 UTCEPSS rescore
- 2026-06-27 03:07 UTCEPSS rescore
- 2026-06-24 06:21 UTCNVD updateCVSS v3 → 9.8
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-23 21:31 UTCEPSS rescore
- 2026-06-17 17:51 UTCEPSS rescore
- 2026-06-17 17:51 UTCEPSS rescore
- 2026-06-15 17:47 UTCEPSS rescore
- 2026-06-15 17:47 UTCEPSS rescore
- 2026-06-09 20:47 UTCOSV refresh
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 06:09 UTCEPSS rescore
- 2026-06-05 06:09 UTCEPSS rescore
- 2026-06-05 06:09 UTCEPSS rescore
- 2026-06-01 13:51 UTCEPSS rescore
Show 6 moreShow fewer
- 2026-06-01 13:51 UTCEPSS rescore
- 2026-05-31 00:15 UTCEPSS rescore
- 2026-05-31 00:15 UTCEPSS rescore
- 2026-05-27 13:39 UTCEPSS rescore
- 2026-05-27 13:39 UTCEPSS rescore
- 2026-05-24 17:37 UTCEG score recompute
Publicly available exploits
(5 references)Working exploit code is in the public domain (1 Metasploit module) (3 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCdiegaccio/Craft-CMS-ExploitFirst seen Jan 29, 2024
CVE-2023-41892 Reverse Shell
Open source ↗ - GitHub PoC0xfalafel/CraftCMS_CVE-2023-41892First seen Dec 26, 2023
Exploit for CVE-2023-41892
Open source ↗ - GitHub PoCzaenhaxor/CVE-2023-41892First seen Oct 6, 2023
CVE-2023-41892 - Craft CMS Remote Code Execution (RCE)
Open source ↗ - Metasploitexploit/linux/http/craftcms_unauth_rce_cve_2023_41892✓ verifiedFirst seen Sep 13, 2023
Craft CMS unauthenticated Remote Code Execution (RCE)
Open source ↗ - Nucleihttp/cves/2023/CVE-2023-41892.yamlFirst seen Jan 1, 2023
CraftCMS < 4.4.15 - Unauthenticated Remote Code Execution
Open source ↗
Related CVEs(same CWE)
Same CWE
10 shownCWE-94
Frequently asked(5)
What is CVE-2023-41892?
When was CVE-2023-41892 disclosed?
Is CVE-2023-41892 actively exploited?
What is the CVSS score of CVE-2023-41892?
How do I remediate CVE-2023-41892?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2023-41892
Is Your Infrastructure Affected by CVE-2023-41892?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.