Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Craft CMS

Craft CMS Vendor Cyber Rating & Cyber Score

craftcms.com

Craft is a content-first CMS that aims to make life enjoyable for developers and content managers alike.


Craft CMS A.I CyberSecurity Scoring

Craft CMS
Company Information
Website:https://craftcms.com/
Employees number:6
Number of followers:2,090
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:craftcms.com
Craft CMS Risk Score (AI oriented)
Between 700 and 749
logo
Craft CMSTechnology, Information and Internet
Updated:
04/04/2026
732/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Craft CMS Global Score (TPRM)
xxxx
logo
Craft CMSTechnology, Information and Internet
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Craft CMS
Craft CMSModerate
Current Score
732Ba (MODERATE)
01000
2 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
734Before Incident
MAY 2026
733Before Incident
APRIL 2026
733Before Incident
MARCH 2026
737Before Incident
Vulnerability
20 Mar 2026Craft CMS
Craft CMS: CISA Warns of Craft CMS Code Injection Vulnerability Exploited in Attacks

Critical Craft CMS Vulnerability (CVE-2025-32432) Actively Exploited in the Wild

732After Incident
CRITICAL-5
CRA1774268712
Critical Craft CMS Vulnerability (CVE-2025-32432) Actively Exploited in the Wild A severe code injection vulnerability in Craft CMS (CVE-2025-32432) has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog after confirmed active exploitation. The flaw, classified under CWE-94 (Improper Control of Code Generation), allows remote, unauthenticated attackers to execute arbitrary code on vulnerable servers. Craft CMS, a widely used enterprise content management system, is at high risk due to this vulnerability. Successful exploitation grants attackers full control over affected systems, enabling data exfiltration, website defacement, or lateral movement into internal networks. While it remains unclear whether the flaw is being used in ransomware campaigns, its potential for initial access makes it a prime target for threat actors, including state-sponsored groups and access brokers. CISA added CVE-2025-32432 to the KEV catalog on March 20, 2026, mandating federal agencies under Binding Operational Directive (BOD) 22-01 to patch by April 3, 2026. Though the directive applies only to government entities, CISA recommends all organizations adopt the same urgency in remediation. Unpatched Craft CMS instances exposed to the internet are highly visible targets, likely already being scanned and exploited by automated attack tools. Mitigation requires immediate patching via vendor updates, with temporary workarounds such as disabling the vulnerable component recommended if patching is delayed. Organizations are also advised to monitor web access logs for suspicious activity.
INCIDENT DETAILS -
TYPE
Code Injection
MOTIVATION
Data exfiltrationInitial accessLateral movement
IMPACT
Data Compromised: Potential data exfiltrationSystems Affected: Craft CMS serversOperational Impact: Full system control by attackersBrand Reputation Impact: Potential website defacement
DATA BREACH
Data Exfiltration: Potential
FEBRUARY 2026
737Before Incident
JANUARY 2026
736Before Incident
DECEMBER 2025
736Before Incident
NOVEMBER 2025
735Before Incident
OCTOBER 2025
735Before Incident
SEPTEMBER 2025
734Before Incident
AUGUST 2025
734Before Incident
JULY 2025
733Before Incident
MAY 2025
764Before Incident
Cyber Attack
29 May 2025Craft CMS
Craft CMS (Content Management System users)

Exploitation of CVE-2025-32432 in Craft CMS by Mimo Threat Operation to Distribute MimoLoader, Cryptocurrency Mining Malware, and Proxyware

732After Incident
HIGH-32
CRA4550545113025
The Mimo threat group exploited a maximum-severity vulnerability (CVE-2025-32432) in Craft CMS to deploy MimoLoader, a malicious payload distributing cryptocurrency mining malware (XMRig) and residential proxyware (IPRoyal). The attack began with initial access via a Turkish IP address, where threat actors installed a web shell to execute persistence scripts. These scripts terminated existing XMRig processes before deploying the Mimo Loader, which then injected both the cryptocurrency miner and proxyware onto compromised systems.The rapid weaponization of CVE-2025-32432—from disclosure to active exploitation—demonstrates Mimo’s high operational agility. While the primary impact involves unauthorized resource consumption (CPU/memory for mining) and proxy network abuse, the breach also risks further lateral movement if left unchecked. Organizations using Craft CMS face operational disruption, reputational damage, and potential financial losses from cryptojacking. The attack does not explicitly mention data exfiltration or ransomware, but the persistence mechanisms suggest long-term compromise risks.
INCIDENT DETAILS -
TYPE
cyberattackexploitation of vulnerabilitymalware distributioncryptojackingproxyware deployment
MOTIVATION
financial gain (cryptocurrency mining)proxyware deployment for residential IP exploitationopportunistic exploitation of newly disclosed vulnerabilities
IMPACT
potential system performance degradation due to cryptocurrency miningunauthorized proxyware (IPRoyal) usagepotential reputational damage due to compromise and malware deployment

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Craft CMS ?
?
What was Craft CMS's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Craft CMS's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Craft CMS's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Craft CMS's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Craft CMS's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Craft CMS's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Craft CMS's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Craft CMS's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Craft CMS's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Craft CMS's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Craft CMS's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Craft CMS's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Craft CMS ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Craft CMS's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?