Tech

US government warns this popular CMS software has a worrying security flaw

Share
Share


  • CISA adds Craft CMS bug to its KEV catalog
  • The bug was found in Craft CMS versions 4 and 5
  • It allows for remote code execution

The US Government’s Cybersecurity and Infrastructure Security Agency (CISA) has added a new bug in Craft CMS versions 4 and 5 to its Known Exploited Vulnerabilities (KEV) catalog, ringing the alarm for abuse in the wild.

The vulnerability is a remote code execution (RCE) flaw tracked as CVE-2025-23209, but we don’t know too many details about it, other than the fact exploitation is not that straightforward.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
Could the ‘Angry Magpie’ save your business from insider threat and data-related attacks?
Tech

Could the ‘Angry Magpie’ save your business from insider threat and data-related attacks?

Browsers are the new frontline, but today’s DLP can’t see the real...

Smart surfaces could represent a powerless solution to multipath signal interference
Tech

Smart surfaces could represent a powerless solution to multipath signal interference

This study demonstrates a passive metasurface technology that uses a time-varying mechanism...

Dual scalable annealing processors overcome capacity and precision limits
Tech

Dual scalable annealing processors overcome capacity and precision limits

The proposed system enables simultaneous expansion of the number of spins and...

All-organic solar cells achieve record efficiency by doubling previous performance
Tech

All-organic solar cells achieve record efficiency by doubling previous performance

Example of damage to the lower layer of a solar cell disposal...