CVE-2025-14532CRITICAL 9.8EPSS p40.9%
CVE-2025-14532CVE-2025-14532
Description
DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can result in Remote Code Execution.
This issue was fixed in versions above 5.0.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.54% probability of exploitation · percentile 40.9% · 2026-06-19T12:03:05Z |
| Published | 2026-03-02 |
| Last modified | 2026-03-05 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Unrestricted Upload of File with Dangerous Typecwe-434 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.