Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior. Note that attackers must have administrator access to the Craft Control Panel for this to work. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.
Metrics
Affected Vendors & Products
References
History
Tue, 06 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Jan 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Craftcms
Craftcms craft Cms |
|
| Vendors & Products |
Craftcms
Craftcms craft Cms |
Mon, 05 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior. Note that attackers must have administrator access to the Craft Control Panel for this to work. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue. | |
| Title | Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior | |
| Weaknesses | CWE-470 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-06T19:04:15.687Z
Reserved: 2025-12-17T20:22:35.081Z
Link: CVE-2025-68455
Updated: 2026-01-06T14:26:31.834Z
Status : Received
Published: 2026-01-05T22:15:52.593
Modified: 2026-01-06T19:16:05.097
Link: CVE-2025-68455
No data.
OpenCVE Enrichment
Updated: 2026-01-06T14:16:21Z