INITIALIZING
📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global phishing Multiple sectors HIGH 25m Global insider Cybersecurity Services CRITICAL 34m Global ransomware Multiple sectors (U.S. companies) CRITICAL 48m Global malware Financial Services, Cryptocurrency CRITICAL 1h Global malware Technology and Cloud Services HIGH 1h Global general Financial Services and E-commerce MEDIUM 1h Global data_breach Social Media and Communications CRITICAL 1h Global general Cybersecurity Operations HIGH 2h Global phishing Technology and Consumer Services HIGH 2h Global data_breach Multiple sectors HIGH 2h Global phishing Multiple sectors HIGH 25m Global insider Cybersecurity Services CRITICAL 34m Global ransomware Multiple sectors (U.S. companies) CRITICAL 48m Global malware Financial Services, Cryptocurrency CRITICAL 1h Global malware Technology and Cloud Services HIGH 1h Global general Financial Services and E-commerce MEDIUM 1h Global data_breach Social Media and Communications CRITICAL 1h Global general Cybersecurity Operations HIGH 2h Global phishing Technology and Consumer Services HIGH 2h Global data_breach Multiple sectors HIGH 2h Global phishing Multiple sectors HIGH 25m Global insider Cybersecurity Services CRITICAL 34m Global ransomware Multiple sectors (U.S. companies) CRITICAL 48m Global malware Financial Services, Cryptocurrency CRITICAL 1h Global malware Technology and Cloud Services HIGH 1h Global general Financial Services and E-commerce MEDIUM 1h Global data_breach Social Media and Communications CRITICAL 1h Global general Cybersecurity Operations HIGH 2h Global phishing Technology and Consumer Services HIGH 2h Global data_breach Multiple sectors HIGH 2h
Vulnerabilities

CVE-2025-68454

High ⚡ Exploit Available
Craft CMS Authenticated Remote Code Execution via Twig SSTI (CVE-2025-68454)
CWE-1336 — Weakness Type
Published: Jan 5, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

Craft is a platform for creating digital experiences. Versions 5.0.0-RC1 through 5.8.20 and 4.0.0-RC1 through 4.16.16 are vulnerable to potential authenticated Remote Code Execution via Twig SSTI. For this to work, users must have administrator access to the Craft Control Panel, and allowAdminChanges must be enabled, which is against Craft CMS' recommendations for any non-dev environment. Alternatively, a non-administrator account with allowAdminChanges disabled can be used, provided access to the System Messages utility is available. It is possible to craft a malicious payload using the Twig `map` filter in text fields that accept Twig input under Settings in the Craft control panel or using the System Messages utility, which could lead to a RCE. Users should update to the patched versions (5.8.21 and 4.16.17) to mitigate the issue.

🤖 AI Executive Summary

Craft CMS versions 4.0.0-RC1 through 4.16.16 and 5.0.0-RC1 through 5.8.20 contain a critical Server-Side Template Injection (SSTI) vulnerability allowing authenticated administrators to execute arbitrary code. Exploitation requires administrator access with allowAdminChanges enabled or access to System Messages utility, enabling attackers to inject malicious Twig payloads through control panel text fields. Active exploits exist and patches are available.

📄 Description (Arabic)

تؤثر هذه الثغرة الأمنية على نظام إدارة المحتوى Craft CMS حيث يمكن للمهاجمين ذوي الصلاحيات الإدارية استغلال ثغرة حقن قوالب Twig من جانب الخادم لتنفيذ تعليمات برمجية عشوائية على الخادم. يتم الاستغلال عبر استخدام فلتر map في Twig ضمن حقول النصوص التي تقبل مدخلات Twig في إعدادات لوحة التحكم أو أداة رسائل النظام. تصنف الثغرة بدرجة خطورة عالية (8.8) وتستهدف بيئات التطوير التي لم يتم تطبيق التوصيات الأمنية عليها. يجب على المؤسسات تحديث النظام فوراً إلى الإصدارات المصححة لمنع الاستغلال المحتمل.

🤖 ملخص تنفيذي (AI)

تحتوي إصدارات Craft CMS من 4.0.0-RC1 حتى 4.16.16 ومن 5.0.0-RC1 حتى 5.8.20 على ثغرة حقن قوالب من جانب الخادم (SSTI) حرجة تسمح للمسؤولين المصادق عليهم بتنفيذ تعليمات برمجية عشوائية. يتطلب الاستغلال صلاحيات المسؤول مع تفعيل allowAdminChanges أو الوصول إلى أداة رسائل النظام، مما يمكّن المهاجمين من حقن أوامر Twig الضارة عبر حقول النصوص في لوحة التحكم. توجد استغلالات نشطة وتحديثات أمنية متاحة.

🤖 AI Intelligence Analysis Analyzed: Feb 28, 2026 07:32
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations using Craft CMS for digital experience platforms, particularly government portals, e-commerce sites, and corporate websites, face significant risk of complete system compromise if administrator credentials are compromised. This vulnerability violates NCA ECC cybersecurity controls and SAMA CSF requirements for secure application development and access control, potentially exposing sensitive citizen data and critical business operations.
🏢 Affected Saudi Sectors
القطاع الحكومي التجارة الإلكترونية الخدمات المالية التعليم الإعلام والنشر الاتصالات وتقنية المعلومات الرعاية الصحية
⚖️ Saudi Risk Score (AI)
9.0
/ 10.0
🔧 Remediation Steps (English)
1. Immediately update Craft CMS to version 4.16.17 or later for version 4.x installations, or version 5.8.21 or later for version 5.x installations to patch the SSTI vulnerability.
2. Disable allowAdminChanges setting in production environments as recommended by Craft CMS security best practices, and restrict access to System Messages utility to only essential personnel with documented business justification.
3. Conduct comprehensive security audit of all administrator accounts, implement multi-factor authentication (MFA) for all privileged accounts, review audit logs for suspicious Twig template modifications, and monitor for indicators of compromise including unexpected system processes or file modifications.
🔧 خطوات المعالجة (العربية)
1. تحديث Craft CMS فوراً إلى الإصدار 4.16.17 أو أحدث للإصدارات 4.x، أو الإصدار 5.8.21 أو أحدث للإصدارات 5.x لإصلاح ثغرة حقن القوالب من جانب الخادم.
2. تعطيل إعداد allowAdminChanges في بيئات الإنتاج وفقاً لأفضل الممارسات الأمنية لـ Craft CMS، وتقييد الوصول إلى أداة رسائل النظام للموظفين الأساسيين فقط مع توثيق المبررات التجارية.
3. إجراء مراجعة أمنية شاملة لجميع حسابات المسؤولين، وتطبيق المصادقة متعددة العوامل (MFA) لجميع الحسابات ذات الصلاحيات العالية، ومراجعة سجلات التدقيق للكشف عن تعديلات مشبوهة في قوالب Twig، ومراقبة مؤشرات الاختراق بما في ذلك العمليات غير المتوقعة أو تعديلات الملفات.
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC-1-1: Cybersecurity Governance ECC-2-1: Asset Management ECC-3-4: Vulnerability Management ECC-4-1: Access Control ECC-5-1: Secure Development ECC-6-2: Security Monitoring
🔵 SAMA CSF
SAMA-CR-1.2: Asset Inventory SAMA-CR-2.3: Vulnerability Assessment SAMA-CR-3.1: Identity and Access Management SAMA-CR-4.2: Security Event Logging SAMA-CR-5.1: Incident Response
🟡 ISO 27001:2022
A.8.8: Management of Technical Vulnerabilities A.9.2: User Access Management A.12.6: Technical Vulnerability Management A.14.2: Security in Development and Support Processes A.16.1: Management of Information Security Incidents
📦 Affected Products / CPE 8 entries
craftcms:craft_cms
craftcms:craft_cms
craftcms:craft_cms:4.0.0
craftcms:craft_cms:4.0.0
craftcms:craft_cms:4.0.0
craftcms:craft_cms:4.0.0
craftcms:craft_cms:5.0.0
craftcms:craft_cms:5.0.0
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-1336
EPSS0.43%
Exploit ✓ Yes
Patch ✓ Yes
Published 2026-01-05
Source Feed nvd
Views 1
🇸🇦 Saudi Risk Score
9.0
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
exploit-available patch-available CWE-1336
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.