CVE-2025-57811: Craft CMS

High severity, CVSS 7.2. EPSS: 0.9% chance of exploitation in the next 30 days.

Craft is a platform for creating digital experiences. From versions 4.0.0-RC1 to 4.16.5 and 5.0.0-RC1 to 5.8.6, there is a potential remote code execution vulnerability via Twig SSTI (Server-Side Template Injection). This is a follow-up to CVE-2024-52293. This vulnerability has been patched in versions 4.16.6 and 5.8.7.

Affected products

  • Craft CMS Craft CMS: from 4.1.0, before 4.16.6 (fixed in 4.16.6); from 5.1.0, before 5.8.7 (fixed in 5.8.7); version 4.0.0 only; version 5.0.0 only

Published 2025-08-25. Last modified 2026-06-17.