CVE-2025-68437 | Craft CMS up to 4.16.16/5.8.20 server-side request forgery (GHSA-x27p-wfqw-hfcc / EUVD-2026-0845)
A vulnerability was found in Craft CMS up to 4.16.16/5.8.20. It has been rated as critical. This vulnerability affects unknown code. This manipulation causes server-side request forgery.
This vulnerability is handled as CVE-2025-68437. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.