CVE-2025-68436
MEDIUMCraft CMS 4.0.0.1-4.16.16 and 5.0.0-RC1-5.8.20 - Authenticated Sensitive Information Exposure via User Profile Photo
Title source: llmDescription
Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/craftcms/cms/security/advisories/GHSA-53vf-c43h-j2x9
Patch x_refsource_misc
https://github.com/craftcms/cms/commit/4bcb0db554e273b66ce3b75263a13414c2368fc9
Scores
CVSS v3
6.5
EPSS
0.0023
EPSS Percentile
13.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (4)
craftcms/cms
5.0.0-RC1 - 5.8.21Packagist
craftcms/craft_cms
4.0.0 (4 CPE variants)
craftcms/craft_cms
5.0.0 (2 CPE variants)
craftcms/craft_cms
4.0.0.1 - 4.16.17
Published
Jan 05, 2026
Tracked Since
Feb 18, 2026