CVE Database
/

CVE-2025-46731

Back to search

CVE-2025-46731

Published: May 5, 2025

Modified: May 5, 2025

PUBLISHED

Description

Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13 or 5.6.15 to mitigate the issue.

VendorProductVersions

craftcms

cms

affected
>= 4.0.0-RC1, < 4.14.13
affected
>= 5.0.0-RC1, < 5.6.15

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now