CVE-2025-68436Sensitive Information Exposure in Craft CMS

Severity
4.9MEDIUMNVD
EPSS
0.0%
top 86.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 5

Description

Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16, authenticated users on a Craft installation could potentially expose sensitive assets via their user profile photo via maliciously crafted requests. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

Affected Packages3 packages

Packagistcraftcms/cms5.0.0-RC15.8.21+1
NVDcraftcms/craft_cms4.0.0.14.16.17+3
CVEListV5craftcms/cms>= 4.0.0-RC1, < 4.16.17, >= 5.0.0-RC1, < 5.8.21+1

Patches

🔴Vulnerability Details

3
GHSA
Craft CMS vulnerable to potential information disclosure via unchecked asset relocation2026-01-05
CVEList
Craft CMS vulnerable to potential information disclosure via unchecked asset relocation2026-01-05
OSV
Craft CMS vulnerable to potential information disclosure via unchecked asset relocation2026-01-05

🕵️Threat Intelligence

1
Wiz
CVE-2025-68436 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2025-68436 — Sensitive Information Exposure | cvebase