CVE-2025-25790
foxcms
An arbitrary file upload vulnerability in the component \controller\LocalTemplate.php of FoxCMS v1.2.5 allows attackers to execute arbitrary code via uploading a crafted Zip file.
- CVSS
- 9.8
- EPSS
- 0.89% 55.8% percentile
- CISA KEV
- Not listed
- Published
- 2025.02.27