Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.
CVE-2025-32432
Score elevated to 10.0 because this CVE is listed on the CISA Known Exploited Vulnerabilities catalog (added 2026-03-20), indicating real-world exploitation has been confirmed by US federal agencies. NVD baseline CVSS 10.0 retained for reference. Confidence: HIGH.
- Actively exploited in the wild (CISA-KEV)
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 10.0
- EG Score
- 10.0(high)
- EPSS
- 100.0%
- KEV
- ⚠ Exploited
Published
April 25, 2025
Last Modified
March 20, 2026
Advisory Details (7)
Auto-updated Jul 18, 2026Known Exploited Vulnerabilities Catalog | CISA
Known Exploited Vulnerabilities Catalog | CISA. Listed in CISA Known Exploited Vulnerabilities catalog.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32432SensePost | Investigating an in-the-wild campaign using RCE in CraftCMS
https://sensepost.com/blog/2025/investigating-an-in-the-wild-campaign-using-rce-in-craftcms/Remote Code Execution · Advisory · craftcms/cms · GitHub
https://github.com/craftcms/cms/security/advisories/GHSA-f3gw-9ww9-jmc3commit e1c85441fa47 (craftcms/cms)
Patch available: craftcms/cms 5.10.1 (contains commit e1c85441fa47)
https://github.com/craftcms/cms/commit/e1c85441fa47eeb7c688c2053f25419bc0547b47cms/CHANGELOG.md at 5.x · craftcms/cms · GitHub
https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5617---2025-04-10-criticalcms/CHANGELOG.md at 4.x · craftcms/cms · GitHub
https://github.com/craftcms/cms/blob/4.x/CHANGELOG.md#41415---2025-04-10-criticalcms/CHANGELOG.md at 3.x · craftcms/cms · GitHub
https://github.com/craftcms/cms/blob/3.x/CHANGELOG.md#3915---2025-04-10-criticalAffected Packages
(1 across 1 ecosystem)
Packagist(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| craftcms/cms | 5.0.0 ... 5.6.9.1 (101 versions) | 5.6.17 | — |
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 12× in last 7d / 29× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-22 22:05 UTCEG score recompute
- 2026-07-22 19:40 UTCCISA KEV update
- 2026-07-22 14:30 UTCEG score recompute
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-22 14:07 UTCEPSS rescore
- 2026-07-21 14:37 UTCCISA KEV update
- 2026-07-18 10:51 UTCEG score recompute
- 2026-07-18 10:04 UTCEPSS rescore
- 2026-07-18 10:04 UTCEPSS rescore
- 2026-07-17 08:26 UTCEG score recompute
- 2026-07-16 17:04 UTCCISA KEV update
- 2026-07-16 17:02 UTCEPSS rescore
- 2026-07-15 16:49 UTCCISA KEV update
- 2026-07-15 15:04 UTCCISA KEV update
- 2026-07-14 18:05 UTCCISA KEV update
- 2026-07-13 17:07 UTCCISA KEV update
- 2026-07-10 17:52 UTCCISA KEV update
- 2026-07-07 19:01 UTCCISA KEV update
- 2026-07-07 17:16 UTCCISA KEV update
- 2026-07-06 16:27 UTCEPSS rescore
- 2026-07-06 16:26 UTCEPSS rescore
- 2026-07-01 19:16 UTCCISA KEV update
- 2026-06-29 19:12 UTCCISA KEV update
- 2026-06-25 19:15 UTCCISA KEV update
- 2026-06-25 13:49 UTCEPSS rescore
Show 30 moreShow fewer
- 2026-06-25 13:49 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-23 21:32 UTCEPSS rescore
- 2026-06-23 17:44 UTCCISA KEV update
- 2026-06-18 16:13 UTCCISA KEV update
- 2026-06-16 19:33 UTCCISA KEV update
- 2026-06-15 19:33 UTCCISA KEV update
- 2026-06-15 17:48 UTCEPSS rescore
- 2026-06-14 23:17 UTCEPSS rescore
- 2026-06-12 17:35 UTCCISA KEV update
- 2026-06-11 19:10 UTCCISA KEV update
- 2026-06-09 18:42 UTCCISA KEV update
- 2026-06-09 17:12 UTCCISA KEV update
- 2026-06-08 19:16 UTCCISA KEV update
- 2026-06-08 17:26 UTCCISA KEV update
- 2026-06-08 14:16 UTCEPSS rescore
- 2026-06-08 14:16 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 22:46 UTCEPSS rescore
- 2026-06-05 22:43 UTCCISA KEV update
- 2026-06-04 13:12 UTCEPSS rescore
- 2026-06-04 13:11 UTCEPSS rescore
- 2026-06-03 19:09 UTCCISA KEV update
- 2026-06-02 18:32 UTCCISA KEV update
- 2026-06-01 20:42 UTCCISA KEV update
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-31 00:16 UTCEPSS rescore
- 2026-05-29 22:23 UTCEG score recompute
- 2026-05-29 22:20 UTCCISA KEV update
- 2026-05-29 13:44 UTCEPSS rescore
Publicly available exploits
(8 references)Working exploit code is in the public domain (1 Metasploit module) (5 GitHub PoCs) (1 Exploit-DB entry). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCcd-ratel/CVE-2025-32432First seen May 15, 2026
Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning
Open source ↗ - Exploit-DBEDB-52525First seen Apr 29, 2026
Craft CMS 5.6.16 - RCE
Open source ↗ - GitHub PoCbambooqj/CVE-2025-32432First seen Sep 23, 2025
AI修复生成的CVE-2025-32432的poc
Open source ↗ - Open source ↗GitHub PoCCTY-Research-1/CVE-2025-32432-PoCFirst seen Jun 1, 2025
- GitHub PoCSachinart/CVE-2025-32432First seen Apr 27, 2025
This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability affecting CraftCMS versions 4.x and 5.x. The vulnerability exists in the asset transform generation feature of CraftCMS.
Open source ↗ - GitHub PoCChocapikk/CVE-2025-32432First seen Apr 26, 2025
CraftCMS RCE Checker (CVE-2025-32432)
Open source ↗ - Metasploitexploit/linux/http/craftcms_preauth_rce_cve_2025_32432✓ verifiedFirst seen Apr 14, 2025
Craft CMS Image Transform Preauth RCE (CVE-2025-32432)
Open source ↗ - Nucleihttp/cves/2025/CVE-2025-32432.yamlFirst seen Jan 1, 2025
CraftCMS - Remote Code Execution
Open source ↗
Related CVEs(same CWE)
Same CWE
10 shownCWE-94
Frequently asked(6)
What is CVE-2025-32432?
When was CVE-2025-32432 disclosed?
Is CVE-2025-32432 actively exploited?
What is the CVSS score of CVE-2025-32432?
Which products are affected by CVE-2025-32432?
How do I remediate CVE-2025-32432?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2025-32432
Is Your Infrastructure Affected by CVE-2025-32432?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.