PoC Archive PoC Archive

tag

Cve-2025-32432

  • CVE-2025-32432 web CRITICAL 10 KEV EPSS 100%

    Craft CMS Pre-Auth Remote Code Execution via Session Poisoning + Yii2 PhpManager Gadget (CVE-2025-32432)

    Craft CMS shipped an incomplete patch for the earlier CVE-2023-41892 deserialization RCE, leaving a critical, pre-auth code-injection chain exploitable through the assets/generate-transform action. An unauthenticated attacker first poisons the server-side PHP…

    Patched 2026-07-31