Craft CMS security challenges in spring 2025

A relatively serious security vulnerability was discovered in Craft CMS's underlying codebase in early April 2025. Craft was quick to release an update that fixed it, but many active websites out there are still vulnerable and have not received the update.

Craft cms sikkerhetsutfordring 2025

How we handle security updates

We always offer our clients an operations agreement, where the size depends on the complexity of the website and how active the agreement is.

We offer continuous, quarterly, annual or tailor-made update frequencies for all systems in use. Either within a given version (e.g. Craft CMS 4.x) or actively including full system upgrades, such as from Craft CMS 4 to 5.

Regardless of the size of the agreement, critical security vulnerabilities are something that stands apart from ordinary updates. Such updates must be applied as quickly as at all possible. That is why we have gone through all our client sites and closed the security hole.

There are nevertheless many other websites out there that are affected and still not patched. If you are unsure whether your website is affected, feel free to get in touch with us.

The vulnerability applies to Craft CMS versions 3, 4 and 5. All three versions were fixed in versions 3.9.15, 4.14.15 and 5.6.17.

Read more about the security issue here:

https://craftcms.com/knowledge-base/craft-cms-cve-2025-32432

https://thehackernews.com/2025/04/hackers-exploit-critical-craft-cms.html

https://www.esecurityplanet.com/cybersecurity/craft-cms-flaws-exploited/

Get in touch

Info

hei@vasser.no
944 41 442

Kjølberggata 21 (Factory Tøyen)
0653 OSLO

Instagram LinkedIn

Bi logo invertert Cantec helping people invertert