Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-25789


FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.


Published

2025-02-26T15:15:26.853

Last Modified

2025-04-09T14:08:57.030

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application foxcms foxcms 1.2.5 Yes

References