CVE-2025-68454 | Craft CMS up to 4.16.16/5.8.20 System Message special elements used in a template engine (GHSA-742x-x762-7383 / EUVD-2026-0844)
A vulnerability was found in Craft CMS up to 4.16.16/5.8.20. It has been classified as critical. This vulnerability affects unknown code of the component System Message Handler. The manipulation leads to improper neutralization of special elements used in a template engine.
This vulnerability is uniquely identified as CVE-2025-68454. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.