Vulnerability CVE-2025-32432 (CVSS 10): Craft CMS Hit by Critical RCE Flaw Exploited in the Wild Do Son April 25, 2025 2 minutes read 0 Add as a preferredsource on Google 🔐 Access to This Vulnerability Report Requires Support This article is available to verified supporters only - contribute to read the full report Or choose another support option: Support via PayPal Support via BMC Share this article: Facebook Post LinkedIn Telegramcve-2025-32432-cvss-10-craft-cms-hit-by-critical-rce-flaw-exploited-in-the-wild/')" style="display: inline-flex; align-items: center; justify-content: center; gap: 8px; margin-right: 10px; margin-bottom: 10px; padding: 8px 16px; color: #ffffff; text-decoration: none; border-radius: 4px; font-size: 14px; font-weight: 500; transition: background-color 0.2s; background-color: #475569; border: none; cursor: pointer; font-family: inherit;"> Copy Link Related posts: Craft CMS Zero-Day CVE-2025-32432 Exploited with Metasploit Module Now Public 82,000+ WordPress Sites at Risk: TheGem Theme Vulnerabilities Allow Full Site Takeover PoC Reveals Apple Audio Zero-Day Enabling Remote Code Execution via Malicious Media Files Critical Trend Micro Apex Central Flaws: Pre-Auth RCE (CVSS 9.8) Threatens Your Security Behind the Commit: CVSS 10.0 Bug Lets Attackers Hijack Gogs Servers Written by@DdoS · Security ResearcherDo SonDo Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks. Tags: CMS Exploit Craft CMS CVE-2025-32432 Remote Code Execution security patch Web Security Yii Framework Leave a Reply Cancel replyYou must be logged in to post a comment.