Craft CMS Code Injection Vulnerability
Vendor: Craft CMS
Product: Craft CMS
Added: 2025-06-02
Due Date: 2025-06-23
Description:
Craft CMS contains a code injection vulnerability. Users with affected versions are vulnerable to remote code execution if their php.ini configuration has `register_argc_argv` enabled.
Required Action:
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CWEs: