CVE-2025-32432CISA KEV: Actively Exploited

Craft CMS Code Injection Vulnerability

Published Mar 20, 2026·Updated Mar 20, 2026

Description

Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.

Public Exploits & PoCs8 found

PoC: CVE-2025-32432

This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability affecting CraftCMS versions 4.x and 5.x. The vulnerability exists in the asset transform generation feature of CraftCMS.

13

PoC: CVE-2025-32432

CraftCMS RCE Checker (CVE-2025-32432)

8

PoC: CVE-2025-32432

CVE-2025-32432 checker and exploit

3

PoC: CVE-2025-32432

Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning

1

[POC] GHSA-3mgp-fx93-9xv5 — PoC_CVE-2025-32432

CraftCMS CVE-2025-32432 - Clean PoC

PoC: htb-orion-writeup

Hack The Box - Orion (Easy) | CVE-2025-32432 & CVE-2026-24061

PoC: CVE-2025-32432

AI修复生成的CVE-2025-32432的poc

PoC: Blackash-CVE-2025-32432

CVE-2025-32432

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free