CVE-2025-35939 is a critical vulnerability affecting Craft CMS versions prior to 5.7.5 and 4.15.3. It allows unauthenticated attackers to inject arbitrary content, including PHP code, into server-side session files due to improper sanitization of return URLs. This vulnerability has a CVSS score of 5.3 (Medium) but a FAUCET Risk Score of 99/100, indicating a high potential impact, as it could lead to arbitrary code execution when combined with another vulnerability. Notably, this flaw is actively exploited in the wild, as confirmed by its presence in the KEV catalog, and has garnered significant community discussion, despite a lack of public exploit tools. Organizations using affected Craft CMS versions should prioritize immediate patching to mitigate this severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.15.3CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.7.5CPE matchmatch criteria | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* | ||
>= 0, < 4.15.3CPE match | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* | ||
>= 0, < 5.7.5CPE match | cpe:2.3:a:craftcms:craft_cms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.