CVE advisoryKnown Exploit
CVE-2025-23209
Craft CMS Remote Code Execution Vulnerability.
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A remote code execution vulnerability affects Craft CMS installations with a compromised security key. This could allow attackers to execute arbitrary code, impacting systems and data. Business risk includes potential data breaches and operational disruption. Patches are available for Craft 5.5.8 and 4.13.8.