Skip to main content
CRITICAL CISA KEV

CVE-2025-32432

CVSS v3

10

CRITICAL

EPSS Score

80.4 %

exploit probability

CISA KEV

Yes

known exploited

Exploitation

SSVC status

Description

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.

CISA Known Exploited Vulnerability

Date Added
2026-03-20
Patch Due Date
2026-04-03
Ransomware Use
Unknown

Technical details

Published
2025-04-25
Exploit-DB
EDB-52525

Frequently asked questions

What is CVE-2025-32432?

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.

Is CVE-2025-32432 actively exploited?

Yes. CVE-2025-32432 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 4/3/2026.

What is the CVSS score for CVE-2025-32432?

CVE-2025-32432 has a CVSS v3 base score of 10 (CRITICAL severity).

Is CVE-2025-32432 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 30 free checks/month · Free API key