CVE-2025-68436
MEDIUMCraftcms Craft Cms < 4.16.17 - Information Disclosure
Title source: ruleDescription
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/craftcms/cms/security/advisories/GHSA-53vf-c43h-j2x9
Patch x_refsource_misc
https://github.com/craftcms/cms/commit/4bcb0db554e273b66ce3b75263a13414c2368fc9
Scores
CVSS v3
6.5
EPSS
0.0005
EPSS Percentile
14.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (4)
craftcms/cms
5.0.0-RC1 - 5.8.21Packagist
craftcms/craft_cms
4.0.0 (4 CPE variants)
craftcms/craft_cms
5.0.0 (2 CPE variants)
craftcms/craft_cms
4.0.0.1 - 4.16.17
Published
Jan 05, 2026
Tracked Since
Feb 18, 2026