CVE-2025-23209: Craft CMS Code Injection Vulnerability

High severity, CVSS 8.1. Actively exploited: in CISA KEV since 2025-02-20. EPSS: 21.8% chance of exploitation in the next 30 days.

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security key is affected. This vulnerability has been patched in Craft 5.5.8 and 4.13.8. Users who cannot update to a patched version, should rotate their security keys and ensure their privacy to help migitgate the issue.

Affected products

  • Craft CMS Craft CMS: after 4.0.0, before 4.13.8 (fixed in 4.13.8); after 5.0.0, before 5.5.8 (fixed in 5.5.8); version 4.0.0 only; version 5.0.0 only

Published 2025-01-18. Last modified 2026-06-17.