Vendor

Craft CMS

As of , 4 Craft CMS vulnerabilities are on CISA's list of exploited vulnerabilities; 1 was added in 2026. Patch first: CVE-2025-32432.

Patch first

Patch first
#VulnerabilityProductOur groupListedDeadlineEPSS
1CVE-2025-32432Code InjectionCraft CMS Craft CMSPatch this weekMetasploit module; EPSS 0.990.99
2CVE-2024-56145Code InjectionCraft CMS Craft CMSPatch this weekMetasploit module; EPSS 0.970.97
3CVE-2025-23209Code InjectionCraft CMS Craft CMSPatch soon0.22
4CVE-2025-35939External Control of Assumed-Immutable Web ParameterCraft CMS Craft CMSPatch soon0.01

Added each year

1232025: 3320252026: 112026
Entries CISA added each year, removed ones included. Source: CISA KEV.
Show the numbers
Periodentries added
20253
20261

Used in ransomware

Changes CISA made to these entries

  1. CVE-2025-23209 Craft CMSEdited: description.

Every change we recorded