ZeroHour

Vulnerabilities

6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-60790
ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to v

ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service.

NVD description · AI analysis pending
6.5<1% PoC ×2
  • processwire processwire
CVE-2024-41597
Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment.

Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment. NOTE: this is disputed by the Supplier because the product intentionally accepts anonymous, unauthenticated comments and thus there are fewer situations in which CSRF would be a useful attack technique. Also, the submitted comments are, by default, held for moderator review.

NVD description · AI analysis pending
4.2<1% PoC
  • processwire processwire
CVE-2023-24676
An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the download_zip_url parameter when installing

An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the download_zip_url parameter when installing a new module. NOTE: this is disputed because exploitation requires that the attacker is able to enter requests as an admin; however, a ProcessWire admin is intentionally allowed to install any module that contains any arbitrary code.

NVD description · AI analysis pending
7.21% PoC
  • processwire processwire
CVE-2022-40488
+1 in the same advisory: …40487
ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF).

ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF).

NVD description · AI analysis pending
6.5
group max
<1%
  • processwire processwire
CVE-2020-27467
A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php.

A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php.

NVD description · AI analysis pending
7.516% PoC
  • processwire processwire