CVE-2025-68455

HIGH EPSS 52.4%
Published Jan 5, 20265mo ago · Modified Jun 17, 20261w ago
8.6 CVSS 4.0
High
Find Similar
Published Jan 5, 2026 5mo ago
Last Modified Jun 17, 2026 1w ago

Description

Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior. Note that attackers must have administrator access to the Craft Control Panel for this to work. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.

CVSS Details

Base Score
8.6
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required High
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
52.4% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available

Weaknesses 1

CWE-470

Affected Products 8

VendorProductVersionRange
craftcmscraft_cms*≥4.0.0.1  –  <4.16.17
craftcmscraft_cms*≥5.0.1  –  <5.8.21
craftcmscraft_cms4.0.0any
craftcmscraft_cms4.0.0any
craftcmscraft_cms4.0.0any
craftcmscraft_cms4.0.0any
craftcmscraft_cms5.0.0any
craftcmscraft_cms5.0.0any

References 5

  • github.com https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5821---2025-12-04
    ProductRelease Notes
  • github.com https://github.com/craftcms/cms/commit/27f55886098b56c00ddc53b69239c9c9192252c7
    Patch
  • github.com https://github.com/craftcms/cms/commit/6e608a1a5bfb36943f94f584b7548ca542a86fef
    Patch
  • github.com https://github.com/craftcms/cms/commit/ec43c497edde0b2bf2e39a119cded2e55f9fe593
    Patch
  • github.com https://github.com/craftcms/cms/security/advisories/GHSA-255j-qw47-wjh5
    ExploitVendor Advisory

Remediation

  • github.com https://github.com/craftcms/cms/commit/27f55886098b56c00ddc53b69239c9c9192252c7
    Patch
  • github.com https://github.com/craftcms/cms/commit/6e608a1a5bfb36943f94f584b7548ca542a86fef
    Patch
  • github.com https://github.com/craftcms/cms/commit/ec43c497edde0b2bf2e39a119cded2e55f9fe593
    Patch