Tech

US government warns this popular CMS software has a worrying security flaw

Share
Share


  • CISA adds Craft CMS bug to its KEV catalog
  • The bug was found in Craft CMS versions 4 and 5
  • It allows for remote code execution

The US Government’s Cybersecurity and Infrastructure Security Agency (CISA) has added a new bug in Craft CMS versions 4 and 5 to its Known Exploited Vulnerabilities (KEV) catalog, ringing the alarm for abuse in the wild.

The vulnerability is a remote code execution (RCE) flaw tracked as CVE-2025-23209, but we don’t know too many details about it, other than the fact exploitation is not that straightforward.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Perplexity AI’s Comet browser will streak across the web this month
Tech

Perplexity AI’s Comet browser will streak across the web this month

Perplexity AI’s new WhatsApp integration offers instant fact-checking without leaving the app...

Exploring the ‘Jekyll-and-Hyde tipping point’ in AI
Tech

Exploring the ‘Jekyll-and-Hyde tipping point’ in AI

Attention head (‘AI’) shown in basic form, generates a response to a...