← Back to browse · API

CVE-2025-23209

Severity
HIGH
CVSS
8.1
EPSS
0.04356
Risk score
58.92
CISA KEV
Yes
PoC
No
Published
2025-02-20
Modified
2025-02-20
First seen
2026-08-07
Aliases
EUVD-2025-0208, GHSA-X684-96HH-833X
Products
Craft CMS:Craft CMS, statamic:CMS 4.0.0-RC1, < 4.13.8, statamic:CMS 5.0.0-RC1, < 5.5.5
Sources
cisa.gov CVE-2025-23209
euvd EUVD-2025-0208

Description

Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution.

References