Craft CMS — Craft CMS — Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration has `register_argc_argv` enabled.
Details
EPSS Score
ⓘ
97.45%
99.9th percentile
Confidence
100%
CISA KEV
Date Added
Jun 2, 2025
Patch Due
Jun 23, 2025
Required Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.