Review reviewCritical
CVE-2025-29287
mcms
An arbitrary file upload vulnerability in the ueditor component of MCMS v5.4.3 allows attackers to execute arbitrary code via uploading a crafted file.
- CVSS
- 9.8
- EPSS
- 0.73% 50.5% percentile
- CISA KEV
- Not listed
- Published
- 2025.04.22