All verified exploits

CVE-2025-32432 Craft CMS Unauthenticated RCE

Deterministic critical Craft CMS CISA KEV Added cve-verified-cve-2025-32432

Detects Craft CMS instances running versions 3.0.0 through 5.6.16 where the image transform endpoint accepts non-string handle parameters, enabling PHP object injection via Yii's __class bypass. An unauthenticated attacker can execute arbitrary code by sending a crafted JSON payload to /actions/assets/generate-transform.

Is your app exploitable through CVE-2025-32432?

Scan your domain free