APromptRiskDBThreat intelligence atlas
AI Vulnerability Context

CVE-2025-35939 - Craft CMS Craft CMS

Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulnerability could allow an unauthenticated client to introduce arbitrary values, such as PHP code, to a known local file location on the server. This vulnerability could be chained with CVE-2024-58136 as represented by CVE-2025-32432.

AI Vulnerability ContextCISA KEVCraft CMS

Record summary

A quick snapshot of what this page covers.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEV
CVE ID
CVE-2025-35939
Vendor/project
Craft CMS
Product
Craft CMS
Vulnerability name
Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability
Date added
2025-06-02
Due date
2025-06-23
Known ransomware campaign use
Unknown
CWE-472

Exploit context

What the vulnerability is about.

No description available. The source record only contains identifiers and metadata.

Source

Where this page information comes from.