---
cve: "CVE-2025-46731"
severity: "HIGH"
cvss: 7.3
epss: "1.4%"
vendor: "craftcms"
kev: false
exploited: false
published: "2025-05-05 20:15:21"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-12T08:10:12+02:00"
---

# CVE-2025-46731

> 7.3 HIGH · 🧪 PoC

## Beschreibung

Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be enabled for this to work. Users should update to the patched versions 4.14.13 or 5.6.15 to mitigate the issue.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Hoch | good |
| UI Interaktion | Keine | bad |

## Patch verfügbar (OSV)

- a17667bd7ba7e69c4eb19eb7d13f039a6904e130 (Commit)
- 5ad0b36612ad190c841bd55cc05fcebc299ac1d7 (Commit)

## Referenzen

- <https://github.com/craftcms/cms/security/advisories/GHSA-7c58-g782-9j38>
- <https://github.com/craftcms/cms/security/advisories/GHSA-f3cw-hg6r-chfv>
- <https://craftcms.com/knowledge-base/securing-craft#set-allowAdminChanges-to-false-in-production>
- <http://github.com/craftcms/cms/pull/17026>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-46731) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
