CVE-2025-46731: Craft CMS

High severity, CVSS 7.2. EPSS: 1.5% chance of exploitation in the next 30 days.

Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13 or 5.6.15 to mitigate the issue.

Affected products

  • Craft CMS Craft CMS: from 4.1.0, before 4.14.13 (fixed in 4.14.13); from 5.1.0, before 5.6.15 (fixed in 5.6.15); version 4.0.0 only; version 5.0.0 only

Published 2025-05-05. Last modified 2026-06-17.