HIGHVulnerability
Verified
Global
CISA KEV: Craft CMS Craft CMS — Craft CMS Code Injection Vulnerability
Friday, March 20, 2026 at 12:00 AM UTC·Source: CISA KEV
Updated: Thursday, April 2, 2026 at 05:46 PM UTC
Executive Summary
Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.
Analysis
Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.
Added to CISA Known Exploited Vulnerabilities catalog on 2026-03-20. Remediation due: 2026-04-03.