LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-23209: Craft CMS Code Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 20, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 13, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-23209 to its Known Exploited Vulnerabilities catalog on Feb 20, 2025, with a federal patch deadline of Mar 13, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution.

CVE-2025-23209 is a code injection vulnerability in Craft CMS. Improper validation of the database backup path can allow an attacker to achieve remote code execution on the host. This matters because Craft CMS often powers public-facing websites and administrative interfaces; successful abuse can give an attacker control of the application server and any data it can reach.

Defenders should treat the issue as a high-priority configuration and input-validation flaw. Confirm exact impact, affected releases, and fixed versions against the vendor advisory before acting.

How it works

The vulnerability is classified as CWE-94 (Improper Control of Generation of Code). Craft CMS fails to adequately validate the path used for database backups. An attacker who can influence that path may inject code that the application later executes, resulting in remote code execution under the privileges of the Craft CMS process.

No public exploit details are supplied here. In general, code-injection flaws of this class are abused by supplying crafted input that reaches a file-system or command-construction path the application trusts. The precise request parameters, authentication requirements, and payload format must be verified against the vendor advisory; do not assume unauthenticated access or any particular attack vector without that confirmation.

Am I affected? How to find it in your systems

Craft CMS is a PHP-based content-management system commonly deployed on web servers, often behind reverse proxies or load balancers, and used for marketing sites, blogs, and internal portals. Inventory every instance by searching configuration management databases, web-server document roots, package inventories, and container images for Craft CMS installations and their version strings.

Telemetry alone cannot prove exploitation; correlate findings with the vendor’s indicators of compromise once they are published.

How to remediate

Apply the vendor-supplied update that addresses CVE-2025-23209 as soon as it has been tested in your environment. Follow the CISA-required action: apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Document the change and re-scan the inventory to confirm every instance is updated.

If you can't patch immediately

Until the official update can be deployed, reduce the attack surface with compensating controls.

If your data may have been exposed

Actively exploited vulnerabilities can lead to full server compromise and data theft. Although ransomware use of this specific CVE is not documented, treat any confirmed exploitation as a potential breach. Rotate credentials, review access logs, and preserve forensic evidence. Readers can run a free exposure scan of their email addresses to check whether those addresses appear in known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedCraft CMS · Craft CMS
WeaknessCWE-94
Added to CISA KEVFeb 20, 2025
Federal patch deadlineMar 13, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities