PatchSiren cyber security CVE debrief
CVE-2025-32432 Craft CMS CVE debrief
CVE-2025-32432 is a Craft CMS code injection vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2026-03-20. Because it is KEV-listed, defenders should treat it as actively relevant and follow the vendor’s mitigation guidance immediately. If mitigations are unavailable, CISA directs organizations to follow applicable BOD 22-01 guidance for cloud services or discontinue use of the product.
- Vendor
- Craft CMS
- Product
- Craft CMS
- CVSS
- CRITICAL 10
- CISA KEV
- Listed
- Original CVE published
- 2026-03-20
- Original CVE updated
- 2026-03-20
- Advisory published
- 2026-03-20
- Advisory updated
- 2026-03-20
Who should care
Craft CMS administrators, web application owners, security operations teams, managed service providers, and any organization that runs Craft CMS in production, especially internet-facing deployments.
Technical summary
The supplied corpus identifies CVE-2025-32432 as a Craft CMS code injection issue and confirms it is listed in CISA’s KEV catalog. The corpus does not include affected versions, attack prerequisites, or a fixed version, so the safest posture is to treat all known Craft CMS deployments as needing immediate review against the vendor advisory and the official CVE/NVD records.
Defensive priority
Critical
Recommended defensive actions
- Review the Craft CMS knowledge base advisory and the GitHub security advisory linked in the source notes for vendor-specific remediation steps.
- Apply mitigations per vendor instructions as soon as possible.
- If mitigations are unavailable, follow CISA BOD 22-01 guidance for cloud services or discontinue use of the product.
- Inventory all Craft CMS instances, including internet-facing and externally managed deployments.
- Validate remediation across environments and monitor for unexpected behavior or signs of compromise.
Evidence notes
Evidence in the supplied corpus comes from CISA’s KEV feed entry for Craft CMS. It records the vendor project as Craft CMS, product as Craft CMS, vulnerability name as Craft CMS Code Injection Vulnerability, dateAdded as 2026-03-20, dueDate as 2026-04-03, and requiredAction text directing mitigations or discontinuation if mitigations are unavailable. The corpus does not supply CVSS, affected versions, or exploitation details beyond KEV listing.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-32432 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-32432
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-32432 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-32432
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.