ZeroHour

Vulnerabilities

15 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-12920
A flaw has been found in qianfox FoxCMS up to 1.2.16.

A flaw has been found in qianfox FoxCMS up to 1.2.16. Affected by this vulnerability is the function add/edit of the file app/admin/controller/Product.php. This manipulation of the argument Title causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
1.9<1% PoC ×2
  • foxcms foxcms
CVE-2025-10251
A vulnerability was detected in FoxCMS up to 1.24.

A vulnerability was detected in FoxCMS up to 1.24. Affected by this issue is the function batchCope of the file /app/admin/controller/Images.php. The manipulation of the argument ids results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
2.1<1% PoC
  • foxcms foxcms
CVE-2025-56630
FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file.

FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Column.php file.

NVD description · AI analysis pending
7.3<1%
  • foxcms foxcms
CVE-2025-56435
SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the.

SQL Injection vulnerability in FoxCMS v1.2.6 and before allows a remote attacker to execute arbitrary code via the. file /DataBackup.php and the operation on the parameter id.

NVD description · AI analysis pending
5.3<1%
  • foxcms foxcms
CVE-2025-55422
In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.

In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus.

NVD description · AI analysis pending
8.8<1% PoC
  • foxcms foxcms
CVE-2025-55409
FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article.

FoxCMS 1.2.6, there is a Cross Site Scripting vulnerability in /index.php/article. This allows attackers to execute arbitrary code.

NVD description · AI analysis pending
8.8<1% PoC
  • foxcms foxcms
CVE-2025-55420
A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6.

A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is sent via a GET request, it is reflected unsanitized into the HTML response. This permits execution of arbitrary JavaScript code when a logged-in user submits the malicious input.

NVD description · AI analysis pending
8.8<1% PoC
  • foxcms foxcms
CVE-2025-50692
FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.

FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.

NVD description · AI analysis pending
9.8<1% PoC
  • foxcms foxcms
CVE-2025-46154
Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.

Foxcms v1.25 has a SQL time injection in the $_POST['dbname'] parameter of installdb.php.

NVD description · AI analysis pending
8.4<1%
  • foxcms foxcms
CVE-2025-5155
A vulnerability has been found in qianfox FoxCMS 1.2.5 and classified as critical.

A vulnerability has been found in qianfox FoxCMS 1.2.5 and classified as critical. Affected by this vulnerability is the function batchCope of the file app/admin/controller/Article.php. The manipulation of the argument ids leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

NVD description · AI analysis pending
5.3<1% PoC
  • foxcms foxcms
CVE-2025-29181
+1 in the same advisory: …29180
FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.

FOXCMS <= V1.25 is vulnerable to SQL Injection via $param['title'] in /admin/util/Field.php.

NVD description · AI analysis pending
7.2<1%
  • foxcms foxcms
CVE-2025-29306
Unauthenticated RCE in FoxCMS 1.2.5 via case display page

CVE-2025-29306 is a code-injection flaw (CWE-94) in FoxCMS 1.2.5, an open-source content management system, that allows unauthenticated remote code execution through the case display page in the index.html component. A remote attacker needs no privileges and no user interaction (per the CVSS 3.1 vector) to reach the affected page and have the application execute attacker-controlled code on the web server, yielding full confidentiality, integrity, and availability impact (CVSS 9.8, critical). Any deployment running FoxCMS 1.2.5 is affected; the advisory cites only that version, so operators of other releases should confirm their exposure against the vendor's advisories. Exploitation is not yet confirmed in the wild and the issue is not in CISA's KEV, but a public proof-of-concept is available on GitHub and EPSS assigns a high 46.6% probability of exploitation within 30 days.

Do: Upgrade FoxCMS to the newest release available from the vendor — no fixed version is specified in the available data, so confirm the patched version in the project's official release notes before deploying. Until patched, restrict external access to the case display functionality and review web server logs for anomalous requests to the index.html case page and indicators of code execution (unexpected processes, webshells). Given the elevated EPSS (46.6%), prioritize patching internet-facing instances.

9.847% PoC
  • foxcms 1.2.5 (the only version explicitly cited in the CVE description; other versions are not specified in the available data)
unknown (niche, self-hosted open-source CMS; no public install counts or internet-exposure scan data)
CVE-2025-25789
+1 in the same advisory: …25790
FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.

FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.

NVD description · AI analysis pending
9.81% PoC
  • foxcms foxcms