Craft CMS Code Injection Vulnerability

Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.

Published 6 Aug 2026Updated 6 Aug 202615 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.

Affected versions

Craft CMS: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 52525Craft CMS 5.6.16 - RCEbanyamer2026-04-29VerifiedPoC-in-GitHub · Chocapikk/CVE-2025-32432CraftCMS RCE Checker (CVE-2025-32432)★ 10Chocapikk2025-04-26CandidatePoC-in-GitHub · Sachinart/CVE-2025-32432This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability affecting CraftCMS versions 4.x and 5.x. The vulnerability exists in the asset transform generation feature of CraftCMS.★ 27Sachinart2025-04-27CandidatePoC-in-GitHub · CTY-Research-1/CVE-2025-32432-PoC★ 8CTY-Research-12025-06-01CandidatePoC-in-GitHub · bambooqj/CVE-2025-32432AI修复生成的CVE-2025-32432的poc★ 2bambooqj2025-09-23CandidatePoC-in-GitHub · TheMursalin/CVE-2025-32432★ 0TheMursalin2026-04-30CandidatePoC-in-GitHub · cd-ratel/CVE-2025-32432Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning★ 2cd-ratel2026-05-15CandidatePoC-in-GitHub · n40y/PoC_CVE-2025-32432CraftCMS CVE-2025-32432 - Clean PoC★ 0n40y2026-06-24CandidatePoC-in-GitHub · c0gnit00/CVE-2025-32432Exploit, POC for CVE-2025-32432, CraftCMS2Shell★ 4c0gnit002026-07-21CandidatePoC-in-GitHub · theeomega/CVE-2025-32432-POC★ 0theeomega2026-07-23CandidatePoC-in-GitHub · HeltonPojo/CVE-2025-32432★ 0HeltonPojo2026-07-30CandidatePoC-in-GitHub · PsyGuy007-sys/craftcms-cve-2025-32432-rceCraft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research★ 1PsyGuy007-sys2026-08-05CandidatePoC-in-GitHub · EzraMansor/CVE-2025-32432-PoCA simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go★ 0EzraMansor2026-08-07Candidate