Skip to content

Products › Brands

Brand

Craft CMS: actively exploited vulnerabilities

4 vulnerabilities in Craft CMS products (Craft CMS) are in CISA’s catalog of exploited vulnerabilities. Last added: March 20, 2026.

The brand’s general security advisories page, not the advisory for a specific vulnerability (address checked September 28, 2026).

By category

Add just one Craft CMS category to your radar, or open its page.

A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.

Affected products

  • Craft CMS4 vulnerabilities, CMS and websites

Name used by CISA: Craft CMS. Product families: indicative classification by this site.

Patch first

In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this Craft CMS list.

  1. Rank 1

    Craft CMSCVE-2025-32432

    Craft CMS Code Injection Vulnerability

    CVSS severity 10.0critical

    Added Mar 20, 2026

  2. Rank 2

    Craft CMSCVE-2024-56145

    Craft CMS Code Injection Vulnerability

    CVSS severity 9.8critical

    Added Jun 2, 2025

  3. Rank 3

    Craft CMSCVE-2025-23209

    Craft CMS Code Injection Vulnerability

    CVSS severity 8.1high

    Added Feb 20, 2025

  4. Rank 4

    Craft CMSCVE-2025-35939

    Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability

    CVSS severity 5.3medium

    Added Jun 2, 2025

Follow and verify

Indicative classification, based on the vendor and product names given by CISA. How products are classified.