S4E just found a high [ai] pa ssl inspection control
critical·Product Based Web Vulnerabilities·Updated Apr 29, 2025

CVE-2025-32432 Scanner

CVE-2025-32432 Scanner - Remote Code Execution (RCE) vulnerability in CraftCMS

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2025-32432
10.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to remote code execution. This is a high-impact, low-complexity attack vector. This issue has been patched in versions 3.9.15, 4.14.15, and 5.6.17, and is an additional fix for CVE-2023-41892.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
cmsby craftcms
>= 3.0.0-RC1, < 3.9.15
Updated Aug 5, 2026View on NVD →
Detail

CraftCMS is a renowned content management system widely used by developers and businesses to create custom digital experiences. From small businesses to large enterprises, CraftCMS is appreciated for its flexibility and user-friendly design. The CMS allows users to manage website content effortlessly, customize design templates, and integrate third-party extensions. Its usage spans across various industries, from e-commerce to entertainment and media platforms. The platform provides robust features for building both simple and complex digital environments. Due to its wide adoption, maintaining the security integrity of CraftCMS is crucial for all its users globally.

The detected vulnerability, Remote Code Execution (RCE), allows an attacker to execute arbitrary code on a server running a vulnerable version of CraftCMS. This high-severity vulnerability impacts the core framework and can be exploited with minimal complexity. If an attacker successfully exploits this vulnerability, they can gain control over the web server, access sensitive data, and inject malicious scripts into the web application. The RCE vulnerability showcases the importance of timely updates in protecting web environments from hostile activities. Understanding the potential risk level, it's imperative for users to patch their CraftCMS to safeguard their digital assets.

In terms of technical details, this RCE vulnerability is found in the asset transformation component of CraftCMS. By manipulating the JSON body during a POST request to the 'assets/generate-transform' endpoint, attackers can trigger the injection of arbitrary PHP objects. The malicious payload containing crafted JSON is capable of invoking functions that lead to arbitrary code execution. A typical attack involves leveraging insecure object deserialization to run code with the privileges of the web server. Key elements such as the X-CSRF-Token are crucial to bypass the anti-CSRF mechanisms.

Successful exploitation of this vulnerability could have severe consequences, including full server compromise. An attacker might steal sensitive information such as user credentials and personal data. They could deface websites, disrupt services, or further propagate attacks within the internal network. Businesses could face data breaches, legal liabilities, reputational damage, and financial loss. Given the critical nature of this vulnerability, organizations using vulnerable versions of CraftCMS must prioritize corrective actions.

Solution Advice
  • Update CraftCMS to versions 3.9.15, 4.14.15, or 5.6.17, or later.
  • Implement web application firewalls to detect and block malicious payloads.
  • Restrict network access to critical servers and use IP whitelisting.
  • Conduct regular security audits and vulnerability assessments.
  • Consider disabling PHP deserialization features if not needed.
  • Keep all third-party libraries and server software updated.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.