Vulnerabilities
6 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-60790 | ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to v ProcessWire CMS 3.0.246 allows a low-privileged user with lang-edit to upload a crafted ZIP to Language Support that is auto-extracted without limits prior to validation, enabling resource-exhaustion Denial of Service. NVD description · AI analysis pending | 6.5 | <1% | PoC ×2 |
| — | |
| CVE-2024-41597 | Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment. Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment. NOTE: this is disputed by the Supplier because the product intentionally accepts anonymous, unauthenticated comments and thus there are fewer situations in which CSRF would be a useful attack technique. Also, the submitted comments are, by default, held for moderator review. NVD description · AI analysis pending | 4.2 | <1% | PoC |
| — | |
| CVE-2023-24676 | An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the download_zip_url parameter when installing An issue found in ProcessWire 3.0.210 allows attackers to execute arbitrary code and install a reverse shell via the download_zip_url parameter when installing a new module. NOTE: this is disputed because exploitation requires that the attacker is able to enter requests as an admin; however, a ProcessWire admin is intentionally allowed to install any module that contains any arbitrary code. NVD description · AI analysis pending | 7.2 | 1% | PoC |
| — | |
| CVE-2022-40488 +1 in the same advisory: …40487 | ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF). ProcessWire v3.0.200 was discovered to contain a Cross-Site Request Forgery (CSRF). NVD description · AI analysis pending | 6.5 group max | <1% |
| — | ||
| CVE-2020-27467 | A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php. A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php. NVD description · AI analysis pending | 7.5 | 16% | PoC |
| — |