Craft CMS allows unauthenticated attackers to write arbitrary content (including PHP code) to predictable session file locations on the server. This vulnerability enables potential remote code execution without authentication and is actively being exploited in the wild according to CISA KEV.
Data Source: CIRCL
Confidence: HIGH
Exploitation Method: DIRECT_NETWORK
CVE Published: 2025-05-07
Added to CISA KEV: 2025-06-02 26 DAYS BETWEEN CVE AND KEV
CVE-2025-35939 is a critical security vulnerability affecting Craft CMS that has been confirmed as being actively exploited in the wild [2].
Vulnerability overview CVE-2025-35939 is classified as an external control of assumed-immutable web parameter issue (CWE-472) in Craft CMS. The flaw arises because Craft CMS stores a user-controlled “return URL” in PHP session files without proper sanitization, treating it as if it were a safe, fixe…
Stay up-to-date with world news! Select your topics of interest: Privacy & Data Protection. Training & Knowledge.