CVE-2025-68455
Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior. Note that attackers must have administrator access to the Craft Control Panel for this to work. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.
Vendor
Product
CWE
Yayın Tarihi
2026-01-05 22:15:52
Güncelleme
2026-01-12 18:21:12
Source Identifier
security-advisories@github.com
KEV Date Added
-
Kategoriler
Referanslar
https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5821---2025-12-04
https://github.com/craftcms/cms/commit/27f55886098b56c00ddc53b69239c9c9192252c7
https://github.com/craftcms/cms/commit/6e608a1a5bfb36943f94f584b7548ca542a86fef
https://github.com/craftcms/cms/commit/ec43c497edde0b2bf2e39a119cded2e55f9fe593
https://github.com/craftcms/cms/security/advisories/GHSA-255j-qw47-wjh5
https://github.com/craftcms/cms/security/advisories/GHSA-255j-qw47-wjh5