Feed/CVE-2025-32432
CVE-2025-32432CISA KEV: Actively Exploited

Craft CMS Code Injection Vulnerability

Published Mar 20, 2026·Updated Mar 20, 2026

NVD Description

Craft CMS contains a code injection vulnerability that allows a remote attacker to execute arbitrary code.

Public Exploits & PoCs11 found

PoC: CVE-2025-32432

This repository contains a proof-of-concept exploit script for CVE-2025-32432, a pre-authentication Remote Code Execution (RCE) vulnerability affecting CraftCMS versions 4.x and 5.x. The vulnerability exists in the asset transform generation feature of CraftCMS.

13

PoC: CVE-2025-32432

CraftCMS RCE Checker (CVE-2025-32432)

8

PoC: CVE-2025-32432

CVE-2025-32432 checker and exploit

3

PoC: CVE-2025-32432

Working PoC for CVE-2025-32432 - Craft CMS <= 5.6.16 unauthenticated RCE via Yii2 PhpManager gadget + nginx access.log poisoning

1

[POC] GHSA-3mgp-fx93-9xv5 — PoC_CVE-2025-32432

CraftCMS CVE-2025-32432 - Clean PoC

PoC: CVE-2025-32432-PoC

A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

PoC: craftcms-cve-2025-32432-rce

Craft CMS CVE-2025-32432 command runner adapted from Nicolas Bourras and Orange Cyberdefense research

PoC: CVE-2025-32432

Exploit, POC for CVE-2025-32432, CraftCMS2Shell

PoC: htb-orion-writeup

Hack The Box - Orion (Easy) | CVE-2025-32432 & CVE-2026-24061

PoC: CVE-2025-32432

AI修复生成的CVE-2025-32432的poc

PoC: Blackash-CVE-2025-32432

CVE-2025-32432

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free