CVE-2025-29306
PoCUnauthenticated RCE in FoxCMS 1.2.5 via case display page
CVE-2025-29306 is a code-injection flaw (CWE-94) in FoxCMS 1.2.5, an open-source content management system, that allows unauthenticated remote code execution through the case display page in the index.html component. A remote attacker needs no privileges and no user interaction (per the CVSS 3.1 vector) to reach the affected page and have the application execute attacker-controlled code on the web server, yielding full confidentiality, integrity, and availability impact (CVSS 9.8, critical). Any deployment running FoxCMS 1.2.5 is affected; the advisory cites only that version, so operators of other releases should confirm their exposure against the vendor's advisories. Exploitation is not yet confirmed in the wild and the issue is not in CISA's KEV, but a public proof-of-concept is available on GitHub and EPSS assigns a high 46.6% probability of exploitation within 30 days.
What to do: Upgrade FoxCMS to the newest release available from the vendor — no fixed version is specified in the available data, so confirm the patched version in the project's official release notes before deploying. Until patched, restrict external access to the case display functionality and review web server logs for anomalous requests to the index.html case page and indicators of code execution (unexpected processes, webshells). Given the elevated EPSS (46.6%), prioritize patching internet-facing instances.
| foxcms | 1.2.5 (the only version explicitly cited in the CVE description; other versions are not specified in the available data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An issue in FoxCMS v.1.2.5 allows a remote attacker to execute arbitrary code via the case display page in the index.html component.
- Vendors
- foxcms
- Products
- foxcms
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.