We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-46731

Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTI



Description

Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13 or 5.6.15 to mitigate the issue.

Reserved 2025-04-28 | Published 2025-05-05 | Updated 2025-05-05 | Assigner GitHub_M


HIGH: 7.3CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Problem types

CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine

Product status

>= 4.0.0-RC1, < 4.14.13
affected

>= 5.0.0-RC1, < 5.6.15
affected

References

github.com/...ms/cms/security/advisories/GHSA-7c58-g782-9j38

github.com/...ms/cms/security/advisories/GHSA-f3cw-hg6r-chfv

craftcms.com/knowledge-base/securing-craft

github.com/craftcms/cms/pull/17026

cve.org (CVE-2025-46731)

nvd.nist.gov (CVE-2025-46731)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-46731

Support options

Helpdesk Chat, Email, Knowledgebase