craftcms/cms Security Advisories for 4.13.7 (5)
- 
                        [MEDIUM] Craft CMS Potential Remote Code Execution via Twig SSTIPKSA-cbq7-fhfn-fyt5 CVE-2025-57811 GHSA-crcq-738g-pqvc Affected version: >=5.0.0-RC1,<=5.8.6|>=4.0.0-RC1,<=4.16.5 Reported by: 
 GitHub
- 
                        [MEDIUM] Craft CMS stores arbitrary content provided by unauthenticated users in session filesPKSA-ht16-h36v-hxc7 CVE-2025-35939 GHSA-7vrx-9684-xrf2 Affected version: <4.15.3|>=5.0.0-alpha.1,<5.7.5 Reported by: 
 GitHub
- 
                        [HIGH] Craft CMS Contains a Potential Remote Code Execution Vulnerability via Twig SSTIPKSA-8gxy-mg5h-z15w CVE-2025-46731 GHSA-7c58-g782-9j38 Affected version: >=5.0.0-RC1,<=5.6.14|>=4.0.0-RC1,<=4.14.12 Reported by: 
 GitHub
- 
                        [CRITICAL] Craft CMS Allows Remote Code ExecutionPKSA-5c44-5nbz-c7cq CVE-2025-32432 GHSA-f3gw-9ww9-jmc3 Affected version: >=5.0.0-RC1,<=5.6.16|>=4.0.0-RC1,<=4.14.14|>=3.0.0-RC1,<=3.9.14 Reported by: 
 GitHub
- 
                        [HIGH] Craft CMS has a potential RCE with a compromised security keyPKSA-nfqr-ns8g-wkkx CVE-2025-23209 GHSA-x684-96hh-833x Affected version: >=4.0.0-RC1,<4.13.8|>=5.0.0-RC1,<5.5.5 Reported by: 
 GitHub