Critical Craft CMS Flaw Under Active Exploitation – CISA Issues Urgent Warning
CISA reports a critical security vulnerability (CVE-2025-23209) in Craft CMS versions 4 and 5, scoring 8.1 CVSS, which could enable remote code execution through compromised security keys. The flaw affects versions up to 4.13.8 and 5.5.5, with patches available. Federal agencies must imple...
