CVE-2025-0502: Craftercms

Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS, x86, Windows, 64 bit, ARM allows Directory Indexing, Resource Leak Exposure.This issue affects CrafterCMS: from 4.0.0 before 4.0.8, from 4.1.0 before 4.1.6.

Affected products

  • Craftercms Craftercms: from 4.0.0, before 4.0.8 (fixed in 4.0.8); from 4.1.0, before 4.1.6 (fixed in 4.1.6)

Published 2025-01-15. Last modified 2026-06-17.