The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has registered a significant security loophole affecting the Craft content management system (CMS) in its list of Known Exploited Vulnerabilities (KEV). This action was taken due to the presence of ongoing exploitation.
The specific vulnerability in focus is CVE-2025-23209 (Common Vulnerability Scoring System score: 8.1), which impacts versions 4 and 5 of Craft CMS. The vulnerability has already been
The specific vulnerability in focus is CVE-2025-23209 (Common Vulnerability Scoring System score: 8.1), which impacts versions 4 and 5 of Craft CMS. The vulnerability has already been
