CVE-2025-23209: Craft CMS Code Injection Vulnerability. Craft CMS contains
Craft CMS Code Injection Vulnerability. Craft CMS contains a code injection vulnerability caused by improper validation of the database backup path, ultimately enabling remote code execution.
- CISA KEV-listed (remediation due 2025-03-13)
- EPSS 16.4% (95.0% percentile)