---
id: CVE-2025-68455
title: Craft is a platform for creating digital experiences
summary: >-
  Craft is a platform for creating digital experiences. Versions 5.0.0-RC1
  through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential
  authenticated Remote Code Execution via malicious attached Behavior. Note that
  attackers mu…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-470
vendor: craftcms
product: craft_cms
affected:
  - 'craft_cms >= 4.0.0.1, < 4.16.17'
  - 'craft_cms >= 5.0.1, < 5.8.21'
  - craft_cms = 4.0.0
  - craft_cms = 5.0.0
patched:
  - craft_cms 5.8.21
published: '2026-01-05'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T22:10:00.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-68455'
references:
  - url: 'https://github.com/craftcms/cms/blob/5.x/CHANGELOG.md#5821---2025-12-04'
    label: security-advisories@github.com
  - url: >-
      https://github.com/craftcms/cms/commit/27f55886098b56c00ddc53b69239c9c9192252c7
    label: security-advisories@github.com
  - url: >-
      https://github.com/craftcms/cms/commit/6e608a1a5bfb36943f94f584b7548ca542a86fef
    label: security-advisories@github.com
  - url: >-
      https://github.com/craftcms/cms/commit/ec43c497edde0b2bf2e39a119cded2e55f9fe593
    label: security-advisories@github.com
  - url: 'https://github.com/craftcms/cms/security/advisories/GHSA-255j-qw47-wjh5'
    label: security-advisories@github.com
  - url: 'https://github.com/craftcms/cms/security/advisories/GHSA-255j-qw47-wjh5'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00944
epssPercentile: 0.59608
ingestedAt: '2026-09-30T22:27:27.697Z'
---

## Overview

Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior. Note that attackers must have administrator access to the Craft Control Panel for this to work. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.

## Affected

- `craft_cms >= 4.0.0.1, < 4.16.17`
- `craft_cms >= 5.0.1, < 5.8.21`
- `craft_cms = 4.0.0`
- `craft_cms = 5.0.0`

## Remediation

Upgrade past the affected range:

- `craft_cms 5.8.21`
