Back to search
CVE-2025-46731
Published: May 5, 2025
Modified: May 5, 2025
PUBLISHED
Description
Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13 or 5.6.15 to mitigate the issue.
| Vendor | Product | Versions |
|---|---|---|
craftcms | cms | affected >= 4.0.0-RC1, < 4.14.13affected >= 5.0.0-RC1, < 5.6.15 |
Weaknesses (CWE)
References
https://github.com/craftcms/cms/security/advisories/GHSA-7c58-g782-9j38
x_refsource_CONFIRM
http://github.com/craftcms/cms/pull/17026
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now