CVE-2025-32432
CRITICAL KEV NUCLEICraftCMS - Remote Code Execution
Title source: nucleiDescription
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.
Exploits (8)
nomisec
WORKING POC
1 stars
by CTY-Research-1 · poc
https://github.com/CTY-Research-1/CVE-2025-32432-PoC
github
WORKING POC
by Acczdy · pythonpoc
https://github.com/Acczdy/CVE-Vault/tree/master/CVE-2025-32432
metasploit
WORKING POC
EXCELLENT
by Nicolas Bourras (Orange Cyberdefense), Valentin Lobstein · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/craftcms_preauth_rce_cve_2025_32432.rb
Nuclei Templates (1)
CraftCMS - Remote Code Execution
CRITICALby iamnoooob,rootxharsh,pdresearch
Shodan:
http.component:"Craft CMS"
References (7)
Scores
CVSS v3
10.0
EPSS
0.8837
EPSS Percentile
99.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Details
CISA KEV
2026-03-20
VulnCheck KEV
2025-04-18
ENISA EUVD
EUVD-2025-12521
CWE
CWE-94
Status
published
Products (5)
craftcms/cms
3.0.0-RC1 - 3.9.15Packagist
craftcms/cms
>= 3.0.0-RC1, < 3.9.15
craftcms/cms
>= 4.0.0-RC1, < 4.14.15
craftcms/cms
>= 5.0.0-RC1, < 5.6.17
craftcms/craft_cms
3.0.0 - 3.9.15
Published
Apr 25, 2025
KEV Added
Mar 20, 2026
Tracked Since
Feb 18, 2026