Composer package intelligence
craftcms/cms Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting the Composer package craftcms/cms, including the gap beyond CISA KEV, confidence assessments, and sensor observations.
- Total KEVs
- 4
- Known exploited vulnerabilities affecting craftcms/cms
- In CISA KEV
- 4
- Records also listed in the official catalog
- Beyond CISA KEV
- 0
- Additional exploited vulnerabilities absent from CISA KEV
- Sensor Observed
- 0
- craftcms/cms KEVs with sensor-observed exploitation activity
Review craftcms/cms exploitation against the versions you run
All four exploited craftcms/cms vulnerabilities tracked here are also listed in CISA KEV.
- 100%
- Covered by CISA
- 0%
- Beyond CISA
Attested craftcms/cms vulnerabilities
4 known exploited vulnerabilities affecting this package.
| Vulnerability | CISA KEV | Added |
|---|---|---|
|
CVE-2025-32432
Craft CMS Allows Remote Code Execution |
In CISA | 01 Jun 2026 |
|
CVE-2025-35939
Craft CMS stores user-provided content in session files |
In CISA | 01 Jun 2026 |
|
CVE-2024-56145
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms |
In CISA | 01 Jun 2026 |
|
CVE-2025-23209
Potential RCE with a compromised security key in craft/cms |
In CISA | 20 Feb 2025 |
Recurring weakness patterns
Improper Control of Generation of Code ('Code Injection') and External Control of Assumed-Immutable Web Parameter account for mapped occurrences across this craftcms/cms KEV portfolio.