logo

CISA Warns of Craft CMS Code Injection Flaw Exploited in Active Attacks

ID: 53de78a7-894a-5d1a-9af4-8794f197d93e

STIX ID: report--53de78a7-894a-5d1a-9af4-8794f197d93e

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-23

Date Updated: 2026-04-22

Author: Divya

...
...

CISA added CVE-2025-32432 (CVSS v3.1 10.0) to its Known Exploited Vulnerabilities catalog after active in-the-wild exploitation was observed. The flaw is an insecure deserialization/code injection in Craft CMS (affecting 3.x, 4.x, and 5.x branches) that allows unauthenticated remote code execution via a poisoned session file and a Yii framework gadget chain; vendors released patches (3.9.15, 4.14.15, 5.6.17) and organizations are urged to patch immediately, monitor for webshells/reverse shells, and comply with CISA remediation deadlines.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.