HIGHVulnerability
Verified
Global

CISA KEV: Craft CMS Craft CMS — Craft CMS Code Injection Vulnerability

Friday, March 20, 2026 at 12:00 AM UTC·Source: CISA KEV

Updated: Thursday, April 2, 2026 at 05:46 PM UTC

Executive Summary

Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.

Analysis

Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code. Added to CISA Known Exploited Vulnerabilities catalog on 2026-03-20. Remediation due: 2026-04-03.

Indicators of Compromise (1)

CVE (1)
CVE-2025-32432
Source Attribution

Originally published by CISA KEV on Mar 20, 2026. Verified by: CISA.

Related Threats