Craft CMS
cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*
- >= 5.0.0-RC1, < 5.5.5
- >= 4.0.0-RC1, < 4.13.8
This vulnerability is being actively exploited in the wild.
A remote code execution vulnerability has been identified in Craft CMS versions 4 and 5, specifically in installations where the security key has been compromised. Users running an unpatched version of Craft with a vulnerable security key are at risk.
Exploitation of this vulnerability allows for remote code execution on the affected server.
Users can update to Craft CMS versions 5.5.8 or 4.13.8, where this vulnerability has been patched. For those unable to update, it is recommended to rotate the security key and ensure its privacy.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.