CVE-2025-23209
KEVmassCode Injection via Database Backup Path in Craft CMS Enables RCE
CISA: Craft CMS Code Injection Vulnerability
Craft CMS contains a code injection flaw (CWE-94) in which the path used for database backups is not properly validated, allowing attacker-controlled input to be executed as code. An attacker who can influence the database-backup path — typically through an authenticated admin session or the utility that triggers a backup — can achieve remote code execution on the server running Craft CMS. Per CISA, the affected product is Craft CMS with no specific version range provided, so all deployments should be checked against the vendor's advisory for affected and fixed releases. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-20, confirming exploitation in the wild; EPSS assigns a 21.8% probability of exploitation within 30 days (97th percentile), no public proof-of-concept is known, and ransomware use is unconfirmed.
What to do: Apply the vendor's patched release per Craft's security advisory, or follow CISA's required action to apply mitigations or discontinue use if mitigations are unavailable; verify your installed Craft CMS version against the vendor's affected-versions list. Until patched, restrict access to admin utilities that trigger database backups and review web/application logs for unusual backup-path activity or signs of compromise.
| Craft CMS | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security key is affected. This vulnerability has been patched in Craft 5.5.8 and 4.13.8. Users who cannot update to a patched version, should rotate their security keys and ensure their privacy to help migitgate the issue.
- Affected
- Craft CMS Craft CMS
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- craftcms
- Products
- craft cms
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H