More

    US government warns this popular CMS software has a worrying security flaw




    • CISA adds Craft CMS bug to its KEV catalog
    • The bug was found in Craft CMS versions 4 and 5
    • It allows for remote code execution

    The US Government’s Cybersecurity and Infrastructure Security Agency (CISA) has added a new bug in Craft CMS versions 4 and 5 to its Known Exploited Vulnerabilities (KEV) catalog, ringing the alarm for abuse in the wild.

    The vulnerability is a remote code execution (RCE) flaw tracked as CVE-2025-23209, but we don’t know too many details about it, other than the fact exploitation is not that straightforward.

    https://cdn.mos.cms.futurecdn.net/B73DML5s9XT2asace74Gnd-1200-80.jpg



    Source link

    Latest articles

    spot_imgspot_img

    Related articles

    Leave a reply

    Please enter your comment!
    Please enter your name here

    spot_imgspot_img