🔴 CVE-2025-35939

Craft CMS allows unauthenticated attackers to write arbitrary content (including PHP code) to predictable session file locations on the server. This vulnerability enables potential remote code execution without authentication and is actively being exploited in the wild according to CISA KEV.

← Back to Overview
HIGH_RISK
Risk Level
5.3
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
VERY_HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2025-05-07

Added to CISA KEV: 2025-06-02 26 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-06-04)

CVE-2025-35939 is a critical security vulnerability affecting Craft CMS that has been confirmed as being actively exploited in the wild [2].

Vulnerability Overview
  • Classification: The vulnerability is identified as an "External Control of Assumed-Immutable Web Parameter" (CWE-472) [1].
  • Technical Root Cause: Craft CMS improperly sanitizes user-controlled input (specifically a "return URL" parameter) before storing it in PHP session files [1]. The application treats this input as a safe, fixed parameter, allowing unauthenticated users to inject arbitrary content into session files [1].
Exploitation and Impact
  • Attack Method: Exploitation is possible by unauthenticated remote attackers?id=MA-1341.062025?kagi_q=CVE-2025-35939. By crafting malicious session values, attackers can leverage the application's handling of authentication-required requests to facilitate the injection.
  • Impact: Successful exploitation can lead to Remote Code Execution (RCE) on the affected server.
  • Active Exploitation: The vulnerability has been confirmed as actively exploited in the wild. It has been associated with federal remediation requirements (e.g., BOD 22-01 guidance in the United States).
Mitigation and Status
  • Status: Users are strongly advised to apply patches or mitigations provided by the vendor immediately.
  • Recommendation: If official patches are not immediately applicable, organizations should follow vendor-specific guidance or, if necessary, discontinue use of the product until the vulnerability is remediated.
*Note: While specific version numbers were not detailed in the provided search results, administrators should check the official Craft CMS security advisories for the exact affected versions and the corresponding security updates.*

Sources

  1. CISA Warns of Craft CMS Code Injection Flaw Exploited in the Wild

    Vulnerability overview CVE-2025-35939 is classified as an external control of assumed-immutable web parameter issue (CWE-472) in Craft CMS. The flaw arises because Craft CMS stores a user-controlled “return URL” in PHP session files without proper sanitization, treating it as if it were a safe, fixe…

  2. Craft CMS: Active exploitation of CVE-2024-56145 and ... - 365TRUST

    Stay up-to-date with world news! Select your topics of interest: Privacy & Data Protection. Training & Knowledge.