Craft CMS A.I CyberSecurity Scoring
Craft CMS
Company Information
Website:https://craftcms.com/
Employees number:6
Number of followers:2,090
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:craftcms.com
Craft CMS Risk Score (AI oriented)
Between 700 and 749
Craft CMSTechnology, Information and Internet
Updated:
04/04/2026
04/04/2026
732/1000
Moderate
Ba
Craft CMS Global Score (TPRM)
xxxx
Craft CMSTechnology, Information and Internet
Score locked

Craft CMSModerate
Current Score
732Ba (MODERATE)
01000
2 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
734
MAY 2026
733
APRIL 2026
733
MARCH 2026
737
Vulnerability
20 Mar 2026 • Craft CMS
Craft CMS: CISA Warns of Craft CMS Code Injection Vulnerability Exploited in Attacks
Critical Craft CMS Vulnerability (CVE-2025-32432) Actively Exploited in the Wild
732
CRITICAL-5
CRA1774268712
Critical Craft CMS Vulnerability (CVE-2025-32432) Actively Exploited in the Wild
A severe code injection vulnerability in Craft CMS (CVE-2025-32432) has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog after confirmed active exploitation. The flaw, classified under CWE-94 (Improper Control of Code Generation), allows remote, unauthenticated attackers to execute arbitrary code on vulnerable servers.
Craft CMS, a widely used enterprise content management system, is at high risk due to this vulnerability. Successful exploitation grants attackers full control over affected systems, enabling data exfiltration, website defacement, or lateral movement into internal networks. While it remains unclear whether the flaw is being used in ransomware campaigns, its potential for initial access makes it a prime target for threat actors, including state-sponsored groups and access brokers.
CISA added CVE-2025-32432 to the KEV catalog on March 20, 2026, mandating federal agencies under Binding Operational Directive (BOD) 22-01 to patch by April 3, 2026. Though the directive applies only to government entities, CISA recommends all organizations adopt the same urgency in remediation.
Unpatched Craft CMS instances exposed to the internet are highly visible targets, likely already being scanned and exploited by automated attack tools. Mitigation requires immediate patching via vendor updates, with temporary workarounds such as disabling the vulnerable component recommended if patching is delayed. Organizations are also advised to monitor web access logs for suspicious activity.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
737
JANUARY 2026
736
DECEMBER 2025
736
NOVEMBER 2025
735
OCTOBER 2025
735
SEPTEMBER 2025
734
AUGUST 2025
734
JULY 2025
733
MAY 2025
764
Cyber Attack
29 May 2025 • Craft CMS
Craft CMS (Content Management System users)
Exploitation of CVE-2025-32432 in Craft CMS by Mimo Threat Operation to Distribute MimoLoader, Cryptocurrency Mining Malware, and Proxyware
732
HIGH-32
CRA4550545113025
The Mimo threat group exploited a maximum-severity vulnerability (CVE-2025-32432) in Craft CMS to deploy MimoLoader, a malicious payload distributing cryptocurrency mining malware (XMRig) and residential proxyware (IPRoyal). The attack began with initial access via a Turkish IP address, where threat actors installed a web shell to execute persistence scripts. These scripts terminated existing XMRig processes before deploying the Mimo Loader, which then injected both the cryptocurrency miner and proxyware onto compromised systems.The rapid weaponization of CVE-2025-32432—from disclosure to active exploitation—demonstrates Mimo’s high operational agility. While the primary impact involves unauthorized resource consumption (CPU/memory for mining) and proxy network abuse, the breach also risks further lateral movement if left unchecked. Organizations using Craft CMS face operational disruption, reputational damage, and potential financial losses from cryptojacking. The attack does not explicitly mention data exfiltration or ransomware, but the persistence mechanisms suggest long-term compromise risks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Craft CMS ??
What was Craft CMS's A.I Rankiteo Cyber Score in May 2026 ??
What was Craft CMS's A.I Rankiteo Cyber Score in April 2026 ??
What was Craft CMS's A.I Rankiteo Cyber Score in March 2026 ??
What was Craft CMS's A.I Rankiteo Cyber Score in February 2026 ??
What was Craft CMS's A.I Rankiteo Cyber Score in January 2026 ??
What was Craft CMS's A.I Rankiteo Cyber Score in December 2025 ??
What was Craft CMS's A.I Rankiteo Cyber Score in November 2025 ??
What was Craft CMS's A.I Rankiteo Cyber Score in October 2025 ??
What was Craft CMS's A.I Rankiteo Cyber Score in September 2025 ??
What was Craft CMS's A.I Rankiteo Cyber Score in August 2025 ??
What was Craft CMS's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Craft CMS's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Craft CMS ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Craft CMS's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?