CISA Identifies Craft CMS Weakness CVE-2025-23209 During Ongoing Breaches

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has registered a significant security loophole affecting the Craft content management system (CMS) in its list of Known Exploited Vulnerabilities (KEV).

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has registered a significant security loophole affecting the Craft content management system (CMS) in its list of Known Exploited Vulnerabilities (KEV). This action was taken due to the presence of ongoing exploitation.
The specific vulnerability in focus is CVE-2025-23209 (Common Vulnerability Scoring System score: 8.1), which impacts versions 4 and 5 of Craft CMS. The vulnerability has already been

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.