CVE-2025-68455 | Craft CMS up to 4.16.16/5.8.20 Control Panel externally-controlled input to select classes or code (GHSA-255j-qw47-wjh5 / EUVD-2026-0824)
A vulnerability identified as problematic has been detected in Craft CMS up to 4.16.16/5.8.20. This issue affects some unknown processing of the component Control Panel. This manipulation causes use of externally-controlled input to select classes or code.
This vulnerability is tracked as CVE-2025-68455. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.