CVE-2024-56145: Craft CMS Code Injection Vulnerability
Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2025-06-02. EPSS: 97.4% chance of exploitation in the next 30 days.
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these users an unspecified remote code execution vector is present. Users are advised to update to version 3.9.14, 4.13.2, or 5.5.2. Users unable to upgrade should disable `register_argc_argv` to mitigate the issue.
Affected products
- Craft CMS Craft CMS: from 3.0.0, before 3.9.14 (fixed in 3.9.14); from 4.0.0, before 4.13.2 (fixed in 4.13.2); from 5.0.0, before 5.5.2 (fixed in 5.5.2)
Published 2024-12-18. Last modified 2026-06-17.