ZeroHour

CVE-2025-23209

KEVmass

Code Injection via Database Backup Path in Craft CMS Enables RCE

CISA: Craft CMS Code Injection Vulnerability

CVSS 3.1
8.1 high
EPSS
22%p98
Published
()
KEV added
AI analysis

Craft CMS contains a code injection flaw (CWE-94) in which the path used for database backups is not properly validated, allowing attacker-controlled input to be executed as code. An attacker who can influence the database-backup path — typically through an authenticated admin session or the utility that triggers a backup — can achieve remote code execution on the server running Craft CMS. Per CISA, the affected product is Craft CMS with no specific version range provided, so all deployments should be checked against the vendor's advisory for affected and fixed releases. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-20, confirming exploitation in the wild; EPSS assigns a 21.8% probability of exploitation within 30 days (97th percentile), no public proof-of-concept is known, and ransomware use is unconfirmed.

What to do: Apply the vendor's patched release per Craft's security advisory, or follow CISA's required action to apply mitigations or discontinue use if mitigations are unavailable; verify your installed Craft CMS version against the vendor's affected-versions list. Until patched, restrict access to admin utilities that trigger database backups and review web/application logs for unusual backup-path activity or signs of compromise.

Affected
Craft CMS
Estimated exposure
masson the order of hundreds of thousands of sites (~10^5; third-party web-technology trackers report Craft CMS on roughly 250,000+ live websites) — Estimated from public web-technology trackers (e.g., BuiltWith-class data) that count Craft CMS across hundreds of thousands of live sites, noting that exploitation requires reaching the database-backup code path, typically via an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been compromised. Anyone running an unpatched version of Craft with a compromised security key is affected. This vulnerability has been patched in Craft 5.5.8 and 4.13.8. Users who cannot update to a patched version, should rotate their security keys and ensure their privacy to help migitgate the issue.

CISA Known Exploited Vulnerability
Affected
Craft CMS Craft CMS
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
craftcms
Products
craft cms
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news