Tech

US government warns this popular CMS software has a worrying security flaw

Share
Share


  • CISA adds Craft CMS bug to its KEV catalog
  • The bug was found in Craft CMS versions 4 and 5
  • It allows for remote code execution

The US Government’s Cybersecurity and Infrastructure Security Agency (CISA) has added a new bug in Craft CMS versions 4 and 5 to its Known Exploited Vulnerabilities (KEV) catalog, ringing the alarm for abuse in the wild.

The vulnerability is a remote code execution (RCE) flaw tracked as CVE-2025-23209, but we don’t know too many details about it, other than the fact exploitation is not that straightforward.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Need faster internet? Researchers just sent data at crazy speeds without a single cable
Tech

Need faster internet? Researchers just sent data at crazy speeds without a single cable

Researchers set new wireless data record over 4.6km with infrared Data beams...

Online sellers are losing billions to fake chargebacks in 2025 – and it’s you and me paying the price
Tech

Online sellers are losing billions to fake chargebacks in 2025 – and it’s you and me paying the price

Fraudulent chargebacks are no longer rare, they’re a rising epidemic draining billions...

NYT Connections hints and answers for Sunday, May 4 (game #693)
Tech

NYT Connections hints and answers for Sunday, May 4 (game #693)

Looking for a different day? A new NYT Connections puzzle appears at...