CVE-2025-32432 | Craft CMS up to 3.9.14/4.14.14/5.6.16 code injection (GHSA-f3gw-9ww9-jmc3)
A vulnerability, which was classified as critical, has been found in Craft CMS up to 3.9.14/4.14.14/5.6.16. Affected by this vulnerability is an unknown functionality. The manipulation leads to code injection.
This vulnerability is documented as CVE-2025-32432. The attack can be initiated remotely. Additionally, an exploit exists.
It is advisable to upgrade the affected component.