Detects Craft CMS instances running versions 3.0.0 through 5.6.16 where the image transform endpoint accepts non-string handle parameters, enabling PHP object injection via Yii's __class bypass. An unauthenticated attacker can execute arbitrary code by sending a crafted JSON payload to /actions/assets/generate-transform.
Is your app exploitable through CVE-2025-32432?
Scan your domain free