<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Craft CMS</title><description>Actively exploited vulnerabilities affecting Craft CMS products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/craft-cms.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-32432 — Craft CMS Code Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-32432</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-32432</guid><description>This vulnerability in Craft CMS allows unauthenticated remote attackers to inject and execute arbitrary code on affected servers. Because exploitation requires no credentials, any internet-facing Craft CMS installation is at serious risk of full server compromise. Successful exploitation could lead to data theft, site defacement, backdoor installation, or use of the server as a pivot point for further attacks within the network.</description><pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate><category>Craft CMS</category><category>Craft CMS</category></item><item><title>CVE-2024-56145 — Craft CMS Code Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2024-56145</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2024-56145</guid><description>Craft CMS contains a code injection flaw that allows attackers to execute arbitrary code remotely on affected servers. The vulnerability is specifically exploitable when the PHP runtime setting `register_argc_argv` is enabled in `php.ini` — a non-default but not uncommon configuration. If exploited, an attacker could gain full control of the web server environment, making this a critical risk for any organization running a vulnerable Craft CMS version with that PHP setting active.</description><pubDate>Mon, 02 Jun 2025 00:00:00 GMT</pubDate><category>Craft CMS</category><category>Craft CMS</category></item><item><title>CVE-2025-35939 — Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-35939</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-35939</guid><description>This Craft CMS flaw lets unauthenticated attackers manipulate web parameters to write arbitrary content — including PHP code — to known file locations on the server. On its own that&apos;s serious, but it becomes critical when chained with CVE-2024-58136 (tracked as CVE-2025-32432), which can turn this file-write primitive into full remote code execution. No login is required, meaning any internet-facing Craft CMS installation is at risk of complete server compromise.</description><pubDate>Mon, 02 Jun 2025 00:00:00 GMT</pubDate><category>Craft CMS</category><category>Craft CMS</category></item></channel></rss>