CVE-2025-23209
Exploited in the Wild
✓ Confirmed 0-Day
Triaged: March 5, 2026
2 articles
EPSS Score
Source: FIRST.org · 2026-05-24
16.39%
probability
This CVE has a 16.39% probability
of being exploited in the next 30 days.
0%
Top 95.0th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Attack Intelligence
Craft CMS RCE exploit chain used in zero-day attacks to steal data
BleepingComputer
Apr 25, 2025
Signal Intelligence
Confidence
85%
EPSS
16.39%
Mentions
2
Last Seen
Apr 25, 2025
CNA Information
Analyst Note
CVE-2025-23209 is a recent RCE vulnerability (published 2025-01-18) in Craft CMS with explicit zero-day attack confirmation in the BleepingComputer article title. The vulnerability affects unpatched Craft 4 and 5 installations, and patches were released (5.5.8 and 4.13.8). The timing between publication and active exploitation in the wild, combined with authoritative source naming it a zero-day attack, supports confirmed classification.
Triage Info
Decided atMar 05, 2026